7.5
    High

    CVE-2021-0313

    Last Modified: 21 Nov 2024

    In isWordBreakAfter of LayoutUtils.cpp, there is a possible way to slow or crash a TextView due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-9, Android-10, Android-11, Android-8.0, Android-8.1; Android ID: A-170968514.

    Published:11 Jan 2021
    6.8
    Medium

    CVE-2021-0308

    Last Modified: 21 Nov 2024

    In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11, Android-8.0; Android ID: A-158063095.

    Published:11 Jan 2021
    7.8
    High

    CVE-2021-0306

    Last Modified: 21 Nov 2024

    In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Android versions which allows an app to gain the android.permission.ACTIVITY_RECOGNITION permission without user confirmation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11, Android-8.0, Android-8.1, Android-9, Android-10; Android ID: A-154505240.

    Published:11 Jan 2021
    7.8
    High

    CVE-2021-0302

    Last Modified: 21 Nov 2024

    In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10Android ID: A-155287782

    Published:10 Feb 2021
    Unknown

    CVE-2021-22

    https://github.com/LingerANR/CVE-2021-22-555

    Unknown

    CVE-2020-256480

    https://github.com/dim0x69/cve-2022-25640-exploit

    Unknown

    CVE-2020-72381

    https://github.com/jdordonezn/CVE-2020-72381

    9.8
    Critical

    CVE-2020-36847

    Last Modified: 22 Jul 2025

    The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server.

    Source:Md Amanat Ullah (xSwads)
    Published:12 Jul 2025
    8.8
    High

    CVE-2020-36842

    Last Modified: 8 Apr 2026

    The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpvivid_upload_files AJAX actions that allows low-level authenticated attackers to upload zip files that can be subsequently extracted. This affects versions up to, and including 0.9.35.

    Published:16 Oct 2024
    5.5
    Medium

    CVE-2020-36762

    Last Modified: 21 Nov 2024

    A vulnerability was found in ONS Digital RAS Collection Instrument up to 2.0.27 and classified as critical. Affected by this issue is the function jobs of the file .github/workflows/comment.yml. The manipulation of the argument $COMMENT_BODY leads to os command injection. Upgrading to version 2.0.28 is able to address this issue. The name of the patch is dcaad2540f7d50c512ff2e031d3778dd9337db2b. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-234248.

    Published:18 Jul 2023
    8.3
    High

    CVE-2020-36730

    Last Modified: 8 Apr 2026

    The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists, and/or deactivate the plugin.

    Published:7 Jun 2023
    9.8
    Critical

    CVE-2020-36708

    Last Modified: 8 Apr 2026

    The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <= 1.1.8, Affluent <= 1.1.0, Bonkers <= 1.0.4, Antreas <= 1.0.2, Sparkling <= 2.4.8, and NatureMag Lite <= 1.0.4. This is due to epsilon_framework_ajax_action. This makes it possible for unauthenticated attackers to call functions and achieve remote code execution.

    Published:7 Jun 2023
    6.5
    Medium

    CVE-2020-36603

    Last Modified: 4 Jun 2025

    The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function calls, allowing local, unprivileged users to execute arbitrary code with SYSTEM privileges on Microsoft Windows systems. The mhyprot2.sys driver must first be installed by a user with administrative privileges.

    Published:14 Sept 2022
    7.5
    High

    CVE-2020-36518

    Last Modified: 27 Aug 2025

    jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

    Published:13 Aug 2020
    5.3
    Medium

    CVE-2020-36287

    Last Modified: 21 Nov 2024

    The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to obtain gadget related settings via a missing permissions check.

    Published:9 Apr 2021
    8.1
    High

    CVE-2020-36189

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.

    Published:23 Dec 2020
    8.1
    High

    CVE-2020-36188

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.

    Published:23 Dec 2020
    8.1
    High

    CVE-2020-36187

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.

    Published:23 Dec 2020
    8.1
    High

    CVE-2020-36186

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource.

    Published:23 Dec 2020
    8.1
    High

    CVE-2020-36185

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource.

    Published:23 Dec 2020
    8.8
    High

    CVE-2020-36184

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.

    Published:23 Dec 2020
    8.1
    High

    CVE-2020-36183

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.

    Published:31 Dec 2020
    8.8
    High

    CVE-2020-36182

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.

    Published:31 Dec 2020
    8.8
    High

    CVE-2020-36181

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.

    Published:31 Dec 2020
    8.8
    High

    CVE-2020-36180

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.

    Published:31 Dec 2020
    8.8
    High

    CVE-2020-36179

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.

    Published:31 Dec 2020
    9.8
    Critical

    CVE-2020-36109

    Last Modified: 21 Nov 2024

    ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function of the httpd module that can cause code execution when an attacker constructs malicious data.

    Published:1 Feb 2021
    7.2
    High

    CVE-2020-36079

    Last Modified: 21 Nov 2024

    Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the uploader plugin, check the elFinder box, and then drag and drop files into the Files(elFinder) portion of the UI. This can, for example, place a .php file in the server's uploaded/ directory. NOTE: the vendor disputes this because exploitation can only be performed by an admin who has "lots of other possibilities to harm a site.

    Published:26 Feb 2021
    9.9
    Critical

    CVE-2020-35948

    Last Modified: 1 Jul 2021

    An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite wp-config.php, for example. Alternatively, an attacker could create an exploit chain to obtain a database dump.

    Source:Ron Jost
    Published:1 Jan 2021
    9.8
    Critical

    CVE-2020-35848

    Last Modified: 10 Aug 2021

    Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.

    Source:Brian Ombongi
    Published:30 Dec 2020
    9.8
    Critical

    CVE-2020-35847

    Last Modified: 10 Aug 2021

    Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.

    Source:Brian Ombongi
    Published:30 Dec 2020
    9.8
    Critical

    CVE-2020-35846

    Last Modified: 21 Nov 2024

    Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.

    Published:30 Dec 2020
    9.8
    Critical

    CVE-2020-35775

    Last Modified: 14 Apr 2021

    CITSmart before 9.1.2.23 allows LDAP Injection.

    Source:skysbsb
    Published:15 Feb 2021
    7.2
    High

    CVE-2020-35754

    Last Modified: 29 Jan 2021

    OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab.

    Source:mari0x00
    Published:28 Jan 2021
    7.7
    High

    CVE-2020-35749

    Last Modified: 21 Jan 2021

    Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2.9.3 and earlier for WordPress allows remote attackers to read arbitrary files via the sjb_file parameter to wp-admin/post.php.

    Source:SunCSR Team
    Published:15 Jan 2021
    7.5
    High

    CVE-2020-35737

    Last Modified: 6 Jan 2021

    In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference.

    Source:ALI AL SINAN
    Published:30 Dec 2020
    6.1
    Medium

    CVE-2020-35730

    Last Modified: 4 Nov 2025

    An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.

    Published:28 Dec 2020
    9.8
    Critical

    CVE-2020-35729

    Last Modified: 25 Jan 2021

    KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.

    Source:B3KC4T
    Published:27 Dec 2020
    8.1
    High

    CVE-2020-35728

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).

    Published:23 Dec 2020
    9
    Critical

    CVE-2020-35717

    Last Modified: 21 Nov 2024

    zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).

    Published:1 Jan 2021
    9.8
    Critical

    CVE-2020-35713

    Last Modified: 21 Nov 2024

    Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters to the goform/setSysAdm page.

    Published:26 Dec 2020
    4.3
    Medium

    CVE-2020-35687

    Last Modified: 21 Jan 2021

    PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.

    Source:Mohamed Oosman
    Published:13 Jan 2021
    8.8
    High

    CVE-2020-35682

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).

    Published:13 Mar 2021
    6.1
    Medium

    CVE-2020-35669

    Last Modified: 21 Nov 2024

    An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request.

    Published:24 Dec 2020
    7.5
    High

    CVE-2020-35667

    Last Modified: 21 Nov 2024

    JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials.

    Published:3 Feb 2021
    9.8
    Critical

    CVE-2020-35665

    Last Modified: 24 Dec 2020

    An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation.

    Source:AkkuS
    Published:23 Dec 2020
    8.8
    High

    CVE-2020-35606

    Last Modified: 22 Dec 2020

    Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840.

    Source:AkkuS
    Published:21 Dec 2020
    7.5
    High

    CVE-2020-35598

    Last Modified: 4 Jan 2021

    ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=..%2f URI. NOTE: this might be the same as CVE-2009-4623

    Source:Francisco Javier Santiago Vázquez
    Published:23 Dec 2020
    9.8
    Critical

    CVE-2020-35590

    Last Modified: 21 Nov 2024

    LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configured to accept an arbitrary header for the client source IP address, a malicious user is not limited to perform a brute force attack, because the client IP header accepts any arbitrary string. When randomizing the header input, the login count does not ever reach the maximum allowed retries.

    Published:21 Dec 2020
    7.2
    High

    CVE-2020-35578

    Last Modified: 18 Jan 2021

    An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature is mishandled during a plugin upload, a remote, authenticated admin user can execute operating-system commands.

    Source:Haboob Team
    Published:13 Jan 2021