CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2020-17473

    Last Modified: 21 Nov 2024

    Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to obtain a long-lasting token by impersonating the server.

    Published: 14 Aug 2020
    5.3
    Medium

    CVE-2015-8033

    Last Modified: 21 Nov 2024

    In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.

    Published: 14 Aug 2020
    5.3
    Medium

    CVE-2015-8032

    Last Modified: 21 Nov 2024

    In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.

    Published: 14 Aug 2020
    7.5
    High

    CVE-2020-15694

    Last Modified: 21 Nov 2024

    In Nim 1.2.4, the standard library httpClient fails to properly validate the server response. For example, httpClient.get().contentLength() does not raise any error if a malicious server provides a negative Content-Length.

    Published: 14 Aug 2020
    6.5
    Medium

    CVE-2020-15693

    Last Modified: 21 Nov 2024

    In Nim 1.2.4, the standard library httpClient is vulnerable to a CR-LF injection in the target URL. An injection is possible if the attacker controls any part of the URL provided in a call (such as httpClient.get or httpClient.post), the User-Agent header value, or custom HTTP header names or values.

    Published: 14 Aug 2020
    9.8
    Critical

    CVE-2020-15692

    Last Modified: 21 Nov 2024

    In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument can be a local file path that will be opened in the default explorer. An attacker can pass one argument to the underlying open command to execute arbitrary registered system commands.

    Published: 14 Aug 2020
    7.8
    High

    CVE-2020-9767

    Last Modified: 21 Nov 2024

    A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was running with elevated privileges to elevate their system privileges as well through use of a malicious DLL. Zoom addressed this issue, which only applies to Windows users, in the 5.0.4 client release.

    Published: 14 Aug 2020
    5.9
    Medium

    CVE-2020-9708

    Last Modified: 21 Nov 2024

    The resolveRepositoryPath function doesn't properly validate user input and a malicious user may traverse to any valid Git repository outside the repoRoot. This issue may lead to unauthorized access of private Git repositories as long as the malicious user knows or brute-forces the location of the repository.

    Published: 14 Aug 2020
    6.7
    Medium

    CVE-2020-15145

    Last Modified: 21 Nov 2024

    In Composer-Setup for Windows before version 6.0.0, if the developer's computer is shared with other users, a local attacker may be able to exploit the following scenarios. 1. A local regular user may modify the existing `C:\ProgramData\ComposerSetup\bin\composer.bat` in order to get elevated command execution when composer is run by an administrator. 2. A local regular user may create a specially crafted dll in the `C:\ProgramData\ComposerSetup\bin` folder in order to get Local System privileges. See: https://itm4n.github.io/windows-server-netman-dll-hijacking. 3. If the directory of the php.exe selected by the user is not in the system path, it is added without checking that it is admin secured, as per Microsoft guidelines. See: https://msrc-blog.microsoft.com/2018/04/04/triaging-a-dll-planting-vulnerability.

    Published: 14 Aug 2020
    3
    Low

    CVE-2020-15141

    Last Modified: 21 Nov 2024

    In openapi-python-client before version 0.5.3, there is a path traversal vulnerability. If a user generated a client using a maliciously crafted OpenAPI document, it is possible for generated files to be placed in arbitrary locations on disk.

    Published: 14 Aug 2020
    8
    High

    CVE-2020-15142

    Last Modified: 21 Nov 2024

    In openapi-python-client before version 0.5.3, clients generated with a maliciously crafted OpenAPI Document can generate arbitrary Python code. Subsequent execution of this malicious client is arbitrary code execution.

    Published: 14 Aug 2020
    7.8
    High

    CVE-2020-22722

    Last Modified: 21 Nov 2024

    Rapid Software LLC Rapid SCADA 5.8.0 is affected by a local privilege escalation vulnerability in the ScadaAgentSvc.exe executable file. An attacker can obtain admin privileges by placing a malicious .exe file in the application and renaming it ScadaAgentSvc.exe, which would result in executing the binary as NT AUTHORITY\SYSTEM in a Windows operating system. For example, an attacker can plant a reverse shell from a low privileged user account and by restarting the computer, the malicious service will be started as NT AUTHORITY\SYSTEM by giving the attacker full system access to the remote PC.

    Published: 14 Aug 2020
    7.8
    High

    CVE-2020-22721

    Last Modified: 21 Nov 2024

    A File Upload Vulnerability in PNotes - Andrey Gruber PNotes.NET v3.8.1.2 allows a local attacker to execute arbitrary code via the Miscellaneous " External Programs by uploading the malicious .exe file to the external program.

    Published: 14 Aug 2020
    —
    Unknown

    CVE-2020-22720

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 14 Aug 2020
    6.5
    Medium

    CVE-2019-5591

    Last Modified: 24 Oct 2025

    A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.

    Published: 14 Aug 2020
    9.8
    Critical

    CVE-2020-10055

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (V3.x). Affected applications are delivered with a 3rd party component (BIRT) that contains a remote code execution vulnerability if the Advanced Reporting Engine is enabled. The vulnerability could allow a remote unauthenticated attacker to execute arbitrary commands on the server with SYSTEM privileges.

    Published: 14 Aug 2020
    9.6
    Critical

    CVE-2020-15781

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SICAM WEB firmware for SICAM A8000 RTUs (All versions < V05.30). The login screen does not sufficiently sanitize input, which enables an attacker to generate specially crafted log messages. If an unsuspecting victim views the log messages via the web browser, these log messages might be interpreted and executed as code by the web application. This Cross-Site-Scripting (XSS) vulnerability might compromize the confidentiality, integrity and availability of the web application.

    Published: 14 Aug 2020
    7.8
    High

    CVE-2020-7583

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All versions < V6.0.8). The application does not properly validate the users' privileges when executing some operations, which could allow a user with low permissions to arbitrary modify files that should be protected against writing.

    Published: 14 Aug 2020
    9.8
    Critical

    CVE-2020-7701

    Last Modified: 21 Nov 2024

    madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue.

    Published: 14 Aug 2020
    9.8
    Critical

    CVE-2020-7700

    Last Modified: 21 Nov 2024

    All versions of phpjs are vulnerable to Prototype Pollution via parse_str.

    Published: 14 Aug 2020
    4.4
    Medium

    CVE-2020-9229

    Last Modified: 21 Nov 2024

    FusionCompute 8.0.0 has an information disclosure vulnerability. Due to the properly protection of certain information, attackers may exploit this vulnerability to obtain certain information.

    Published: 14 Aug 2020
    7.5
    High

    CVE-2020-9228

    Last Modified: 21 Nov 2024

    FusionCompute 8.0.0 has an information disclosure vulnerability. Due to the properly protection of certain information, attackers may exploit this vulnerability to obtain certain information.

    Published: 14 Aug 2020
    7.8
    High

    CVE-2020-17462

    Last Modified: 21 Nov 2024

    CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16798.

    Published: 14 Aug 2020
    7.5
    High

    CVE-2019-19643

    Last Modified: 21 Nov 2024

    ise smart connect KNX Vaillant 1.2.839 contain a Denial of Service.

    Published: 14 Aug 2020
    7.2
    High

    CVE-2020-16205

    Last Modified: 21 Nov 2024

    Using a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code (Firmware Versions 1.12.0.25 and prior as well as the limited Versions 1.12.13.2 and 1.12.14.5).

    Published: 14 Aug 2020
    6.1
    Medium

    CVE-2020-12648

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configured in classic editing mode.

    Published: 14 Aug 2020
    6.1
    Medium

    CVE-2019-6112

    Last Modified: 21 Nov 2024

    A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the keyword parameter (aka $search_term or the Search field).

    Published: 14 Aug 2020
    6.1
    Medium

    CVE-2019-7410

    Last Modified: 21 Nov 2024

    There is stored cross site scripting (XSS) in Galileo CMS v0.042. Remote authenticated users could inject arbitrary web script or HTML via $page_title in /lib/Galileo/files/templates/page/show.html.ep (aka the PAGE TITLE Field).

    Published: 14 Aug 2020
    8.8
    High

    CVE-2020-4662

    Last Modified: 21 Nov 2024

    IBM Event Streams 10.0.0 could allow an authenticated user to perform tasks to a schema due to improper authentication validation. IBM X-Force ID: 186233.

    Published: 14 Aug 2020
    5.5
    Medium

    CVE-2020-24352

    Last Modified: 21 Nov 2024

    An issue was discovered in QEMU through 5.1.0. An out-of-bounds memory access was found in the ATI VGA device implementation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati_2d.c while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service.

    Published: 14 Aug 2020
    7.5
    High

    CVE-2020-7711

    Last Modified: 21 Nov 2024

    This affects all versions of package github.com/russellhaering/goxmldsig. There is a crash on nil-pointer dereference caused by sending malformed XML signatures.

    Published: 14 Aug 2020
    7.5
    High

    CVE-2020-7768

    Last Modified: 21 Nov 2024

    The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.

    Published: 14 Aug 2020
    7.8
    High

    CVE-2019-20383

    Last Modified: 21 Nov 2024

    ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges by local users via manipulations involving files and using symbolic links.

    Published: 13 Aug 2020
    7.4
    High

    CVE-2020-7360

    Last Modified: 21 Nov 2024

    An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before April 15, 2020 may allow an authenticated user to escalate privileges by placing a specially crafted DLL file in the search path. This issue was fixed in version 1.0.7, which was released after April 15, 2020. (Note, the version numbering system changed significantly between version 4.3.15 and version 1.0.7.)

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-24343

    Last Modified: 21 Nov 2024

    Artifex MuJS through 1.0.7 has a use-after-free in jsrun.c because of unconditional marking in jsgc.c.

    Published: 13 Aug 2020
    7.1
    High

    CVE-2020-24344

    Last Modified: 21 Nov 2024

    JerryScript through 2.3.0 has a (function({a=arguments}){const arguments}) buffer over-read.

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-24345

    Last Modified: 21 Nov 2024

    JerryScript through 2.3.0 allows stack consumption via function a(){new new Proxy(a,{})}JSON.parse("[]",a). NOTE: the vendor states that the problem is the lack of the --stack-limit option

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-24346

    Last Modified: 21 Nov 2024

    njs through 0.4.3, used in NGINX, has a use-after-free in njs_json_parse_iterator_call in njs_json.c.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-24347

    Last Modified: 21 Nov 2024

    njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_lvlhsh_level_find in njs_lvlhsh.c.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-24348

    Last Modified: 21 Nov 2024

    njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_json_stringify_iterator in njs_json.c.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-24349

    Last Modified: 21 Nov 2024

    njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. NOTE: the vendor considers the issue to be "fluff" in the NGINX use case because there is no remote attack surface.

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-24330

    Last Modified: 21 Nov 2024

    An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop the root gid privilege when no longer needed.

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-0261

    Last Modified: 21 Nov 2024

    In C2 flame devices, there is a possible bypass of seccomp due to a missing configuration file. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-146059841

    Published: 13 Aug 2020
    4.3
    Medium

    CVE-2020-14483

    Last Modified: 21 Nov 2024

    A timeout during a TLS handshake can result in the connection failing to terminate. This can result in a Niagara thread hanging and requires a manual restart of Niagara (Versions 4.6.96.28, 4.7.109.20, 4.7.110.32, 4.8.0.110) and Niagara Enterprise Security (Versions 2.4.31, 2.4.45, 4.8.0.35) to correct.

    Published: 13 Aug 2020
    8.8
    High

    CVE-2020-15947

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in the qm_adm/qm_export_stats_run.do endpoint of Loway QueueMetrics before 19.10.21 allows remote authenticated users to execute arbitrary SQL commands via the exportId parameter.

    Published: 13 Aug 2020
    6.7
    Medium

    CVE-2020-11733

    Last Modified: 21 Nov 2024

    An issue was discovered on Spirent TestCenter and Avalanche appliance admin interface firmware. An attacker, who already has access to an SSH restricted shell, can achieve root access via shell metacharacters. The attacker can then, for example, read sensitive files such as appliance admin configuration source code. This affects Spirent TestCenter and Avalanche products which chassis version <= 5.08. The SSH restricted shell is available with default credentials.

    Published: 13 Aug 2020
    8.8
    High

    CVE-2020-15925

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability at a tpf URI in Loway QueueMetrics before 19.10.21 allows remote authenticated attackers to execute arbitrary SQL commands via the TPF_XPAR1 parameter.

    Published: 13 Aug 2020
    6.4
    Medium

    CVE-2020-13286

    Last Modified: 21 Nov 2024

    For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery.

    Published: 13 Aug 2020
    6.5
    Medium

    CVE-2020-13281

    Last Modified: 21 Nov 2024

    For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature

    Published: 13 Aug 2020
    6.5
    Medium

    CVE-2020-13280

    Last Modified: 21 Nov 2024

    For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message.

    Published: 13 Aug 2020