CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2020-7356

    Last Modified: 21 Nov 2024

    CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and execute SYSTEM commands.

    Published: 6 Aug 2020
    8.4
    High

    CVE-2020-7352

    Last Modified: 21 Nov 2024

    The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to the software shipping with embedded, static RSA private key, an attacker with this key material and local user permissions can effectively send any operating system command to the service for execution in this elevated context. The service listens for such commands on a locally-bound network port, localhost:9978. A Metasploit module has been published which exploits this vulnerability. This issue affects the 2.0.x branch of the software (2.0.12 and earlier) as well as the 1.2.x branch (1.2.64 and earlier). A fix was issued for the 2.0.x branch of the affected software.

    Published: 6 Aug 2020
    8.8
    High

    CVE-2020-15824

    Last Modified: 21 Nov 2024

    In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by default.

    Published: 6 Aug 2020
    5.3
    Medium

    CVE-2020-1710

    Last Modified: 21 Nov 2024

    The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.

    Published: 6 Aug 2020
    7.5
    High

    CVE-2020-1748

    Last Modified: 21 Nov 2024

    A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.

    Published: 6 Aug 2020
    7.5
    High

    CVE-2020-10718

    Last Modified: 21 Nov 2024

    A flaw was found in Wildfly before wildfly-embedded-13.0.0.Final, where the embedded managed process API has an exposed setting of the Thread Context Classloader (TCCL). This setting is exposed as a public method, which can bypass the security manager. The highest threat from this vulnerability is to confidentiality.

    Published: 6 Aug 2020
    4.8
    Medium

    CVE-2020-7068

    Last Modified: 21 Nov 2024

    In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

    Published: 6 Aug 2020
    7.5
    High

    CVE-2020-16845

    Last Modified: 21 Nov 2024

    Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.

    Published: 6 Aug 2020
    6.1
    Medium

    CVE-2020-9036

    Last Modified: 21 Nov 2024

    Jeedom through 4.0.38 allows XSS.

    Published: 5 Aug 2020
    7.4
    High

    CVE-2020-17366

    Last Modified: 21 Nov 2024

    An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent routing systems by strategically withholding RPKI Route Origin Authorisation ".roa" files or X509 Certificate Revocation List files from the RPKI relying party's view.

    Published: 5 Aug 2020
    8.8
    High

    CVE-2020-13404

    Last Modified: 21 Nov 2024

    The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection.

    Published: 5 Aug 2020
    7.5
    High

    CVE-2020-7298

    Last Modified: 21 Nov 2024

    Unexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real time scanning via a specially crafted object making a specific function call.

    Published: 5 Aug 2020
    5.3
    Medium

    CVE-2020-15132

    Last Modified: 21 Nov 2024

    In Sulu before versions 1.6.35, 2.0.10, and 2.1.1, when the "Forget password" feature on the login screen is used, Sulu asks the user for a username or email address. If the given string is not found, a response with a `400` error code is returned, along with a error message saying that this user name does not exist. This enables attackers to retrieve valid usernames. Also, the response of the "Forgot Password" request returns the email address to which the email was sent, if the operation was successful. This information should not be exposed, as it can be used to gather email addresses. This problem was fixed in versions 1.6.35, 2.0.10 and 2.1.1.

    Published: 5 Aug 2020
    7.5
    High

    CVE-2020-15127

    Last Modified: 21 Nov 2024

    In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, essentially killing the entire ingress data plane. GET requests to /shutdown on port 8090 of the Envoy pod initiate Envoy's shutdown procedure. The shutdown procedure includes flipping the readiness endpoint to false, which removes Envoy from the routing pool. When running Envoy (For example on the host network, pod spec hostNetwork=true), the shutdown manager's endpoint is accessible to anyone on the network that can reach the Kubernetes node that's running Envoy. There is no authentication in place that prevents a rogue actor on the network from shutting down Envoy via the shutdown manager endpoint. Successful exploitation of this issue will lead to bad actors shutting down all instances of Envoy, essentially killing the entire ingress data plane. This is fixed in version 1.7.0.

    Published: 5 Aug 2020
    6.5
    Medium

    CVE-2020-15112

    Last Modified: 21 Nov 2024

    In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.go. This could cause issues when WAL entries are being read during consensus as an arbitrary etcd consensus participant could go down from a runtime panic when reading the entry.

    Published: 5 Aug 2020
    6.1
    Medium

    CVE-2020-16254

    Last Modified: 21 Nov 2024

    The Chartkick gem through 3.3.2 for Ruby allows Cascading Style Sheets (CSS) Injection (without attribute).

    Published: 5 Aug 2020
    6.1
    Medium

    CVE-2020-16192

    Last Modified: 21 Nov 2024

    LimeSurvey 4.3.2 allows reflected XSS because application/controllers/LSBaseController.php lacks code to validate parameters.

    Published: 5 Aug 2020
    6.1
    Medium

    CVE-2020-17364

    Last Modified: 21 Nov 2024

    USVN (aka User-friendly SVN) before 1.0.9 allows XSS via SVN logs.

    Published: 5 Aug 2020
    6.7
    Medium

    CVE-2020-8607

    Last Modified: 21 Nov 2024

    An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a system crash or potentially lead to code execution in kernel mode. An attacker must already have obtained administrator access on the target machine (either legitimately or via a separate unrelated attack) to exploit this vulnerability.

    Published: 5 Aug 2020
    8.1
    High

    CVE-2020-16253

    Last Modified: 21 Nov 2024

    The PgHero gem through 2.6.0 for Ruby allows CSRF.

    Published: 5 Aug 2020
    4.3
    Medium

    CVE-2020-16252

    Last Modified: 21 Nov 2024

    The Field Test gem 0.2.0 through 0.3.2 for Ruby allows CSRF.

    Published: 5 Aug 2020
    6.1
    Medium

    CVE-2020-13819

    Last Modified: 21 Nov 2024

    Extreme EAC Appliance 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.

    Published: 5 Aug 2020
    9.8
    Critical

    CVE-2020-13921

    Last Modified: 21 Nov 2024

    **Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.

    Published: 5 Aug 2020
    8.2
    High

    CVE-2020-4481

    Last Modified: 21 Nov 2024

    IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181848.

    Published: 5 Aug 2020
    3.7
    Low

    CVE-2020-4243

    Last Modified: 21 Nov 2024

    IBM Security Identity Governance and Intelligence 5.2.6 Virtual Appliance could allow a remote attacker to obtain sensitive information using man in the middle techniques due to not properly invalidating session tokens. IBM X-Force ID: 175420.

    Published: 5 Aug 2020
    9.8
    Critical

    CVE-2020-5608

    Last Modified: 21 Nov 2024

    CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R8.03.01 allows a remote unauthenticated attacker to bypass authentication and send altered communication packets via unspecified vectors.

    Published: 5 Aug 2020
    9.8
    Critical

    CVE-2020-5609

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R8.03.01 allows a remote unauthenticated attacker to create or overwrite arbitrary files and run arbitrary commands via unspecified vectors.

    Published: 5 Aug 2020
    9.8
    Critical

    CVE-2020-17353

    Last Modified: 21 Nov 2024

    scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.

    Published: 5 Aug 2020
    9.8
    Critical

    CVE-2020-13151

    Last Modified: 21 Nov 2024

    Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query. It attempts to restrict code execution by disabling os.execute() calls, but this is insufficient. Anyone with network access can use a crafted UDF to execute arbitrary OS commands on all nodes of the cluster at the permission level of the user running the Aerospike service.

    Published: 5 Aug 2020
    6.5
    Medium

    CVE-2017-18112

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability in the logging feature. The affected versions are before version 4.8.3.

    Published: 5 Aug 2020
    6.5
    Medium

    CVE-2020-15106

    Last Modified: 21 Nov 2024

    In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is stored in the length field of a WAL file and no additional validation is done on this data. Therefore, it is possible to forge an extremely large frame size that can unintentionally panic at the expense of any RAFT participant trying to decode the WAL.

    Published: 5 Aug 2020
    5.7
    Medium

    CVE-2020-15113

    Last Modified: 21 Nov 2024

    In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the os.MkdirAll. This function does not perform any permission checks when a given directory path exists already. A possible workaround is to ensure the directories have the desired permission (700).

    Published: 5 Aug 2020
    7.7
    High

    CVE-2020-15114

    Last Modified: 21 Nov 2024

    In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway.

    Published: 5 Aug 2020
    5.5
    Medium

    CVE-2020-15704

    Last Modified: 21 Nov 2024

    The modprobe child process in the ./debian/patches/load_ppp_generic_if_needed patch file incorrectly handled module loading. A local non-root attacker could exploit the MODPROBE_OPTIONS environment variable to read arbitrary root files. Fixed in 2.4.5-5ubuntu1.4, 2.4.5-5.1ubuntu2.3+esm2, 2.4.7-1+2ubuntu1.16.04.3, 2.4.7-2+2ubuntu1.3, 2.4.7-2+4.1ubuntu5.1, 2.4.7-2+4.1ubuntu6. Was ZDI-CAN-11504.

    Published: 5 Aug 2020
    5.8
    Medium

    CVE-2020-15115

    Last Modified: 21 Nov 2024

    etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess or brute-force users' passwords with little computational effort.

    Published: 5 Aug 2020
    6.5
    Medium

    CVE-2020-15136

    Last Modified: 21 Nov 2024

    In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on endpoints identified in DNS SRV records for a given domain, which occurs in the discoverEndpoints function. No authentication is performed against endpoints provided in the --endpoints flag. This has been fixed in versions 3.4.10 and 3.3.23 with improved documentation and deprecation of the functionality.

    Published: 5 Aug 2020
    6.5
    Medium

    CVE-2020-3702

    Last Modified: 21 Nov 2024

    u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8053, IPQ4019, IPQ8064, MSM8909W, MSM8996AU, QCA9531, QCN5502, QCS405, SDX20, SM6150, SM7150

    Published: 5 Aug 2020
    5.3
    Medium

    CVE-2020-15109

    Last Modified: 21 Nov 2024

    In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering address validations. This vulnerability allows a malicious customer to craft request data with parameters that allow changing the address of the current order without changing the shipment costs associated with the new shipment. All stores with at least two shipping zones and different costs of shipment per zone are impacted. This problem comes from how checkout permitted attributes are structured. We have a single list of attributes that are permitted across the whole checkout, no matter the step that is being submitted. See the linked reference for more information. As a workaround, if it is not possible to upgrade to a supported patched version, please use this gist in the references section.

    Published: 4 Aug 2020
    6.7
    Medium

    CVE-2020-15135

    Last Modified: 21 Nov 2024

    save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Tokens etc.). The fix introduced in version version 1.05 unintentionally breaks uploading so version v1.0.7 is the fixed version. This is patched by implementing Double submit. The CSRF attack would require you to navigate to a malicious site while you have an active session with Save-Server (Session key stored in cookies). The malicious user would then be able to perform some actions, including uploading/deleting files and adding redirects. If you are logged in as root, this attack is significantly more severe. They can in addition create, delete and update users. If they updated the password of a user, that user's files would then be available. If the root password is updated, all files would be visible if they logged in with the new password. Note that due to the same origin policy malicious actors cannot view the gallery or the response of any of the methods, nor be sure they succeeded. This issue has been patched in version 1.0.7.

    Published: 4 Aug 2020
    6.1
    Medium

    CVE-2020-16847

    Last Modified: 21 Nov 2024

    Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in a GET request, aka CFD-4887.

    Published: 4 Aug 2020
    5.9
    Medium

    CVE-2020-16843

    Last Modified: 21 Nov 2024

    In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. This can result in a denial of service on the microVM when it is configured with a single network interface, and an availability problem for the microVM network interface on which the issue is triggered.

    Published: 4 Aug 2020
    8.1
    High

    CVE-2020-15943

    Last Modified: 21 Nov 2024

    An issue was discovered in the Gantt-Chart module before 5.5.4 for Jira. Due to a missing privilege check, it is possible to read and write to the module configuration of other users. This can also be used to deliver an XSS payload to other users' dashboards. To exploit this vulnerability, an attacker has to be authenticated.

    Published: 4 Aug 2020
    7.1
    High

    CVE-2020-13522

    Last Modified: 21 Nov 2024

    An exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can allow an unprivileged user to delete any file on the filesystem. An attacker can send a malicious IRP to trigger this vulnerability.

    Published: 4 Aug 2020
    7.5
    High

    CVE-2020-15956

    Last Modified: 21 Nov 2024

    ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer overflow and application termination via a malformed payload.

    Published: 4 Aug 2020
    5.4
    Medium

    CVE-2020-15944

    Last Modified: 21 Nov 2024

    An issue was discovered in the Gantt-Chart module before 5.5.5 for Jira. Due to missing validation of user input, it is vulnerable to a persistent XSS attack. An attacker can embed the attack vectors in the dashboard of other users. To exploit this vulnerability, an attacker has to be authenticated.

    Published: 4 Aug 2020
    3.3
    Low

    CVE-2020-13523

    Last Modified: 21 Nov 2024

    An exploitable information disclosure vulnerability exists in SoftPerfect’s RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can cause the disclosure of sensitive information. An attacker can send a malicious IRP to trigger this vulnerability.

    Published: 4 Aug 2020
    7.8
    High

    CVE-2020-16199

    Last Modified: 21 Nov 2024

    Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

    Published: 4 Aug 2020
    3.3
    Low

    CVE-2020-16201

    Last Modified: 21 Nov 2024

    Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple out-of-bounds read vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read information.

    Published: 4 Aug 2020
    7.8
    High

    CVE-2020-16203

    Last Modified: 21 Nov 2024

    Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. An uninitialized pointer may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

    Published: 4 Aug 2020
    8
    High

    CVE-2020-16134

    Last Modified: 21 Nov 2024

    An issue was discovered on Swisscom Internet Box 2, Internet Box Standard, Internet Box Plus prior to 10.04.38, Internet Box 3 prior to 11.01.20, and Internet Box light prior to 08.06.06. Given the (user-configurable) credentials for the local Web interface or physical access to a device's plus or reset button, an attacker can create a user with elevated privileges on the Sysbus-API. This can then be used to modify local or remote SSH access, thus allowing a login session as the superuser.

    Published: 4 Aug 2020