CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2020-10614

    Last Modified: 21 Nov 2024

    In OSIsoft PI System multiple products and versions, an authenticated remote attacker with write access to PI Vision databases could inject code into a display. Unauthorized information disclosure, deletion, or modification is possible if a victim views the infected display.

    Published: 24 Jul 2020
    7.5
    High

    CVE-2020-10604

    Last Modified: 21 Nov 2024

    In OSIsoft PI System multiple products and versions, a remote, unauthenticated attacker could crash PI Network Manager service through specially crafted requests. This can result in blocking connections and queries to PI Data Archive.

    Published: 24 Jul 2020
    5.9
    Medium

    CVE-2020-10600

    Last Modified: 21 Nov 2024

    An authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. This can result in blocking queries to PI Data Archive (2018 SP2 and prior versions).

    Published: 24 Jul 2020
    5.3
    Medium

    CVE-2020-10602

    Last Modified: 21 Nov 2024

    In OSIsoft PI System multiple products and versions, an authenticated remote attacker could crash PI Network Manager due to a race condition. This can result in blocking connections and queries to PI Data Archive.

    Published: 24 Jul 2020
    7.8
    High

    CVE-2020-10606

    Last Modified: 21 Nov 2024

    In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software. This exploitation can result in unauthorized information disclosure, deletion, or modification if the local computer also processes PI System data from other users, such as from a shared workstation or terminal server deployment.

    Published: 24 Jul 2020
    7.8
    High

    CVE-2020-10608

    Last Modified: 21 Nov 2024

    In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure, deletion, or modification.

    Published: 24 Jul 2020
    7.8
    High

    CVE-2020-10610

    Last Modified: 21 Nov 2024

    In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification.

    Published: 24 Jul 2020
    9.8
    Critical

    CVE-2020-12812

    Last Modified: 24 Oct 2025

    An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.

    Published: 24 Jul 2020
    5.5
    Medium

    CVE-2020-8175

    Last Modified: 21 Nov 2024

    Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using specially a crafted JPEG image.

    Published: 24 Jul 2020
    8.8
    High

    CVE-2020-8207

    Last Modified: 21 Nov 2024

    Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running.

    Published: 24 Jul 2020
    8.8
    High

    CVE-2020-15932

    Last Modified: 21 Nov 2024

    Overwolf before 0.149.2.30 mishandles Symbolic Links during updates, causing elevation of privileges.

    Published: 24 Jul 2020
    7.3
    High

    CVE-2020-8326

    Last Modified: 21 Nov 2024

    An unquoted service path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.

    Published: 24 Jul 2020
    7.3
    High

    CVE-2020-8317

    Last Modified: 21 Nov 2024

    A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.

    Published: 24 Jul 2020
    9.9
    Critical

    CVE-2020-15860

    Last Modified: 21 Nov 2024

    Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an authenticated user to execute any application in the backend operating system through the web application, despite the affected application not being published. In addition, it was discovered that it is possible to access any host in the internal domain, even if it has no published applications or the mentioned host is no longer associated with that server farm.

    Published: 24 Jul 2020
    5.4
    Medium

    CVE-2020-14175

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters. The affected versions are before version 7.4.2, and from version 7.5.0 before 7.5.2.

    Published: 24 Jul 2020
    5.4
    Medium

    CVE-2020-15918

    Last Modified: 21 Nov 2024

    Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0.

    Published: 24 Jul 2020
    6.1
    Medium

    CVE-2020-15919

    Last Modified: 21 Nov 2024

    A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0.

    Published: 24 Jul 2020
    9.8
    Critical

    CVE-2020-15920

    Last Modified: 21 Nov 2024

    There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required.

    Published: 24 Jul 2020
    9.8
    Critical

    CVE-2020-15921

    Last Modified: 21 Nov 2024

    Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execution.

    Published: 24 Jul 2020
    9.8
    Critical

    CVE-2020-15922

    Last Modified: 21 Nov 2024

    There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is required.

    Published: 24 Jul 2020
    7.5
    High

    CVE-2020-15923

    Last Modified: 21 Nov 2024

    Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal.

    Published: 24 Jul 2020
    7.5
    High

    CVE-2020-15924

    Last Modified: 21 Nov 2024

    There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is required. The injection point resides in one of the authentication parameters.

    Published: 24 Jul 2020
    5.9
    Medium

    CVE-2020-14340

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final.

    Published: 24 Jul 2020
    7.5
    High

    CVE-2020-24369

    Last Modified: 21 Nov 2024

    ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference.

    Published: 24 Jul 2020
    5.3
    Medium

    CVE-2020-24370

    Last Modified: 5 May 2025

    ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).

    Published: 24 Jul 2020
    7
    High

    CVE-2020-29369

    Last Modified: 21 Nov 2024

    An issue was discovered in mm/mmap.c in the Linux kernel before 5.7.11. There is a race condition between certain expand functions (expand_downwards and expand_upwards) and page-table free operations from an munmap call, aka CID-246c320a8cfe.

    Published: 24 Jul 2020
    7.5
    High

    CVE-2020-7519

    Last Modified: 21 Nov 2024

    A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to compromise a user account.

    Published: 23 Jul 2020
    7.5
    High

    CVE-2020-7518

    Last Modified: 21 Nov 2024

    A CWE-20: Improper input validation vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to modify project configuration files.

    Published: 23 Jul 2020
    5.5
    Medium

    CVE-2020-7517

    Last Modified: 21 Nov 2024

    A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to read user credentials.

    Published: 23 Jul 2020
    7.8
    High

    CVE-2020-7516

    Last Modified: 21 Nov 2024

    A CWE-316: Cleartext Storage of Sensitive Information in Memory vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allow an attacker access to login credentials.

    Published: 23 Jul 2020
    7.8
    High

    CVE-2020-7515

    Last Modified: 21 Nov 2024

    A CWE-321: Use of hard-coded cryptographic key stored in cleartext vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allow an attacker to decrypt a password.

    Published: 23 Jul 2020
    7.8
    High

    CVE-2020-7514

    Last Modified: 21 Nov 2024

    A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker access to the authorization credentials for a device and gain full access.

    Published: 23 Jul 2020
    7.5
    High

    CVE-2020-7491

    Last Modified: 21 Nov 2024

    **VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy debug port account in TCMs installed in Tricon system versions 10.2.0 through 10.5.3 is visible on the network and could allow inappropriate access. This vulnerability was remediated in TCM version 10.5.4.

    Published: 23 Jul 2020
    4.7
    Medium

    CVE-2020-7520

    Last Modified: 21 Nov 2024

    A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists in Schneider Electric Software Update (SESU), V2.4.0 and prior, which could cause execution of malicious code on the victim's machine. In order to exploit this vulnerability, an attacker requires privileged access on the engineering workstation to modify a Windows registry key which would divert all traffic updates to go through a server in the attacker's possession. A man-in-the-middle attack is then used to complete the exploit.

    Published: 23 Jul 2020
    8.8
    High

    CVE-2020-15633

    Last Modified: 21 Nov 2024

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.20B10_BETA. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP requests. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the router. Was ZDI-CAN-10835.

    Published: 23 Jul 2020
    8.8
    High

    CVE-2020-15632

    Last Modified: 21 Nov 2024

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-842 3.13B05 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of HNAP GetCAPTCHAsetting requests. The issue results from the lack of proper handling of sessions. An attacker can leverage this vulnerability to execute arbitrary code in the context of the device. Was ZDI-CAN-10083.

    Published: 23 Jul 2020
    8
    High

    CVE-2020-15631

    Last Modified: 21 Nov 2024

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 1.04B03_HOTFIX WiFi extenders. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the HNAP service, which listens on TCP port 80 by default. When parsing the SOAPAction header, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-10084.

    Published: 23 Jul 2020
    5.3
    Medium

    CVE-2020-11625

    Last Modified: 21 Nov 2024

    An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. Failed web UI login attempts elicit different responses depending on whether a user account exists. Because the responses indicate whether a submitted username is valid or not, they make it easier to identify legitimate usernames. If a login request is sent to ISAPI/Security/sessionLogin/capabilities using a username that exists, it will return the value of the salt given to that username, even if the password is incorrect. However, if a login request is sent using a username that is not present in the database, it will return an empty salt value. This allows attackers to enumerate legitimate usernames, facilitating brute-force attacks. NOTE: this is different from CVE-2020-7057.

    Published: 23 Jul 2020
    9.8
    Critical

    CVE-2020-11624

    Last Modified: 21 Nov 2024

    An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. They do not require users to change the default password for the admin account. They only show a pop-up window suggesting a change but there's no enforcement. An administrator can click Cancel and proceed to use the device without changing the password. Additionally, they disclose the default username within the login.js script. Since many attacks for IoT devices, including malware and exploits, are based on the usage of default credentials, it makes these cameras an easy target for malicious actors.

    Published: 23 Jul 2020
    6.8
    Medium

    CVE-2020-11623

    Last Modified: 21 Nov 2024

    An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. An attacker with physical access to the UART interface could access additional diagnostic and configuration functionalities as well as the camera's bootloader. Successful exploitation could compromise confidentiality, integrity, and availability of the affected system. It could even render the device inoperable.

    Published: 23 Jul 2020
    9.8
    Critical

    CVE-2020-15492

    Last Modified: 21 Nov 2024

    An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP port 85) includes user input into a filesystem access without any further validation. This might allow an unauthenticated attacker to read files on the server via Directory Traversal, or possibly have unspecified other impact.

    Published: 23 Jul 2020
    9.8
    Critical

    CVE-2020-15477

    Last Modified: 21 Nov 2024

    The WebControl in RaspberryTortoise through 2012-10-28 is vulnerable to remote code execution via shell metacharacters in a URI. The file nodejs/raspberryTortoise.js has no validation on the parameter incomingString before passing it to the child_process.exec function.

    Published: 23 Jul 2020
    9.8
    Critical

    CVE-2020-15391

    Last Modified: 21 Nov 2024

    The UI in DevSpace 4.13.0 allows web sites to execute actions on pods (on behalf of a victim) because of a lack of authentication for the WebSocket protocol. This leads to remote code execution.

    Published: 23 Jul 2020
    6.1
    Medium

    CVE-2019-18834

    Last Modified: 21 Nov 2024

    Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Billing Details are mishandled in WCS_Admin_Post_Types in class-wcs-admin-post-types.php.

    Published: 23 Jul 2020
    9.8
    Critical

    CVE-2020-15917

    Last Modified: 21 Nov 2024

    common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.

    Published: 23 Jul 2020
    9.8
    Critical

    CVE-2020-15916

    Last Modified: 21 Nov 2024

    goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parameter.

    Published: 23 Jul 2020
    5.4
    Medium

    CVE-2020-4447

    Last Modified: 21 Nov 2024

    IBM FileNet Content Manager 5.5.3 and 5.5.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 181227.

    Published: 23 Jul 2020
    6.8
    Medium

    CVE-2020-12638

    Last Modified: 21 Nov 2024

    An encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266_NONOS_SDK devices through 3.0.3, and ESP8266_RTOS_SDK devices through 3.3. Broadcasting forged beacon frames forces a device to change its authentication mode to OPEN, effectively disabling its 802.11 encryption.

    Published: 23 Jul 2020
    7.5
    High

    CVE-2020-10922

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the EA-HTTP.exe process. The issue results from the lack of proper input validation prior to further processing user requests. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-10527.

    Published: 23 Jul 2020
    9.8
    Critical

    CVE-2020-10920

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the control service, which listens on TCP port 9999 by default. The issue results from the lack of authentication prior to allowing alterations to the system configuration. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-10493.

    Published: 23 Jul 2020