8.8
    High

    CVE-2020-35576

    Last Modified: 28 Jun 2021

    A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users to execute arbitrary code as root via shell metacharacters, a different vulnerability than CVE-2018-12577.

    Source:Koh You Liang
    Published:25 Jan 2021
    9.8
    Critical

    CVE-2020-35575

    Last Modified: 21 Nov 2024

    A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel. This affects WA901ND devices before 3.16.9(201211) beta, and Archer C5, Archer C7, MR3420, MR6400, WA701ND, WA801ND, WDR3500, WDR3600, WE843N, WR1043ND, WR1045ND, WR740N, WR741ND, WR749N, WR802N, WR840N, WR841HP, WR841N, WR842N, WR842ND, WR845N, WR940N, WR941HP, WR945N, WR949N, and WRD4300 devices.

    Published:26 Dec 2020
    9.8
    Critical

    CVE-2020-35545

    Last Modified: 21 Nov 2024

    Time-based SQL injection exists in Spotweb 1.4.9 via the query string.

    Published:17 Dec 2020
    7.5
    High

    CVE-2020-35498

    Last Modified: 23 Apr 2025

    A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

    Published:10 Feb 2021
    8.1
    High

    CVE-2020-35491

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.

    Published:14 Dec 2020
    8.1
    High

    CVE-2020-35490

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.

    Published:14 Dec 2020
    10
    Critical

    CVE-2020-35489

    Last Modified: 21 Nov 2024

    The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.

    Published:17 Dec 2020
    7.5
    High

    CVE-2020-35488

    Last Modified: 11 Jan 2021

    The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a crafted Syslog payload to the Syslog service. This attack requires a specific configuration. Also, the name of the directory created must use a Syslog field. (For example, on Linux it is not possible to create a .. directory. On Windows, it is not possible to create a CON directory.)

    Source:Guillaume PETIT
    Published:5 Jan 2021
    9.8
    Critical

    CVE-2020-35476

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written to a gnuplot file in the /tmp directory. This file is then executed via the mygnuplot.sh shell script. (tsd/GraphHandler.java attempted to prevent command injections by blocking backticks but this is insufficient.)

    Published:16 Dec 2020
    5.3
    Medium

    CVE-2020-35460

    Last Modified: 5 May 2025

    common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.

    Published:14 Dec 2020
    6.1
    Medium

    CVE-2020-35437

    Last Modified: 4 Jan 2021

    Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.

    Source:icekam
    Published:26 Dec 2020
    6.1
    Medium

    CVE-2020-35416

    Last Modified: 15 Feb 2021

    Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with different request parameters), allows remote attackers to inject arbitrary web script or HTML.

    Source:Andrea Intilangelo
    Published:15 Dec 2020
    9.6
    Critical

    CVE-2020-35391

    Last Modified: 7 Apr 2023

    Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. NOTE: the vulnerability report may suggest that either a ? character must be placed after the RouterCfm.cfg filename, or that the HTTP request headers must be unusual, but it is not known why these are relevant to the device's HTTP response behavior.

    Source:@h454nsec
    Published:1 Jan 2021
    9.8
    Critical

    CVE-2020-35314

    Last Modified: 21 Apr 2021

    A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary code and obtain a webshell via the theme/plugin installer.

    Source:zetc0de
    Published:20 Apr 2021
    9.8
    Critical

    CVE-2020-35313

    Last Modified: 21 Apr 2021

    A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer.

    Source:zetc0de
    Published:20 Apr 2021
    6.1
    Medium

    CVE-2020-35262

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date module and "Keyword" in URL Filter.

    Published:6 Jan 2021
    4.8
    Medium

    CVE-2020-35241

    Last Modified: 5 Jan 2021

    FlatPress 1.0.3 is affected by cross-site scripting (XSS) in the Blog Content component. This vulnerability can allow an attacker to inject the XSS payload in Blog content via the admin panel. Each time any user will go to that blog page, the XSS triggers and the attacker can steal the cookie according to the crafted payload.

    Source:Alperen Ergel
    Published:30 Dec 2020
    8.8
    High

    CVE-2020-35217

    Last Modified: 21 Nov 2024

    Vert.x-Web framework v4.0 milestone 1-4 does not perform a correct CSRF verification. Instead of comparing the CSRF token in the request with the CSRF token in the cookie, it compares the CSRF token in the cookie against a CSRF token that is stored in the session. An attacker does not even need to provide a CSRF token in the request because the framework does not consider it. The cookies are automatically sent by the browser and the verification will always succeed, leading to a successful CSRF attack.

    Published:20 Jan 2021
    9.8
    Critical

    CVE-2020-35191

    Last Modified: 21 Nov 2024

    The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

    Published:17 Dec 2020
    8.8
    High

    CVE-2020-35151

    Last Modified: 22 Dec 2020

    The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection.

    Source:Raffaele Sabato
    Published:21 Dec 2020
    8.8
    High

    CVE-2020-29669

    Last Modified: 21 Nov 2024

    In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password. This process has a vulnerability which can be used to take over the administrator account and results in shell access. As the admin user may read the /etc/shadow file, the password hashes of each user (including root) can be dumped. The root hash can be cracked easily which results in a complete system compromise.

    Published:14 Dec 2020
    9.8
    Critical

    CVE-2020-29667

    Last Modified: 21 Nov 2024

    In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.

    Published:10 Dec 2020
    5.3
    Medium

    CVE-2020-29666

    Last Modified: 21 Nov 2024

    In Lan ATMService M3 ATM Monitoring System 6.1.0, due to a directory-listing vulnerability, a remote attacker can view log files, located in /websocket/logs/, that contain a user's cookie values and the predefined developer's cookie value.

    Published:10 Dec 2020
    7.8
    High

    CVE-2020-29661

    Last Modified: 21 Nov 2024

    A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b.

    Published:4 Dec 2020
    7.2
    High

    CVE-2020-29607

    Last Modified: 29 Jun 2021

    A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.

    Source:Ron Jost
    Published:16 Dec 2020
    7.8
    High

    CVE-2020-29599

    Last Modified: 21 Nov 2024

    ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files. The user-controlled password was not properly escaped/sanitized and it was therefore possible to inject additional shell commands via coders/pdf.c.

    Published:7 Dec 2020
    9.8
    Critical

    CVE-2020-29597

    Last Modified: 5 Jan 2021

    IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to upload files into the server.

    Source:MoeAlBarbari
    Published:7 Dec 2020
    9.8
    Critical

    CVE-2020-29583

    Last Modified: 7 Nov 2025

    Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.

    Published:22 Dec 2020
    4.8
    Medium

    CVE-2020-29477

    Last Modified: 6 Jan 2021

    Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field. This vulnerability can allow an attacker to inject the XSS payload in Field Name and each time any user will open that, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.

    Source:Hemant Patidar
    Published:30 Dec 2020
    4.8
    Medium

    CVE-2020-29475

    Last Modified: 6 Jan 2021

    nopCommerce Store 4.30 is affected by cross-site scripting (XSS) in the Schedule tasks name field. This vulnerability can allow an attacker to inject the XSS payload in Schedule tasks and each time any user will go to that page of the website, the XSS triggers and attacker can able to steal the cookie according to the crafted payload.

    Source:Hemant Patidar
    Published:29 Dec 2020
    4.8
    Medium

    CVE-2020-29471

    Last Modified: 6 Jan 2021

    OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image. An admin can upload a profile image as a malicious code using JavaScript. Whenever anyone will see the profile picture, the code will execute and XSS will trigger.

    Source:Hemant Patidar
    Published:29 Dec 2020
    4.8
    Medium

    CVE-2020-29470

    Last Modified: 6 Jan 2021

    OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Subject field of mail. This vulnerability can allow an attacker to inject the XSS payload in the Subject field of the mail and each time any user will open that mail of the website, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.

    Source:Hemant Patidar
    Published:29 Dec 2020
    5.4
    Medium

    CVE-2020-29469

    Last Modified: 6 Jan 2021

    WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacker to inject the XSS payload in the Setting - Menu and each time any user will visits the website directory, the XSS triggers and attacker can steal the cookie according to the crafted payload.

    Source:Hemant Patidar
    Published:30 Dec 2020
    6.1
    Medium

    CVE-2020-29395

    Last Modified: 1 Dec 2020

    The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.

    Source:B3KC4T
    Published:30 Nov 2020
    7
    High

    CVE-2020-29370

    Last Modified: 21 Nov 2024

    An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the required TID increment, aka CID-fd4d9c7d0c71.

    Published:15 Jun 2020
    4.8
    Medium

    CVE-2020-29364

    Last Modified: 21 Nov 2024

    In NetArt News Lister 1.0.0, the news headlines vulnerable to stored xss attacks. Attackers can inject codes in news titles.

    Published:30 Nov 2020
    8.8
    High

    CVE-2020-29254

    Last Modified: 21 Nov 2024

    TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected system. An attacker could exploit this vulnerability by persuading a user of the interface to follow a maliciously crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected system with the privileges of the user. These action include allowing attackers to submit their own code through an authenticated user resulting in local file Inclusion. If an authenticated user who is able to edit TikiWiki templates visits an malicious website, template code can be edited.

    Published:11 Dec 2020
    4.8
    Medium

    CVE-2020-29240

    Last Modified: 3 Dec 2020

    Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an admin visits the Menu-Pages-Pages Overview section, the XSS will be triggered.

    Source:Sagar Banwa
    Published:2 Dec 2020
    7.5
    High

    CVE-2020-29238

    Last Modified: 13 Apr 2021

    An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensitive information when the server running as reverse proxy via specially crafted request.

    Source:Jai Kumar Sharma
    Published:10 Mar 2021
    5.4
    Medium

    CVE-2020-29233

    Last Modified: 6 Jan 2021

    WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allow an attacker to inject the XSS payload in the Page description and each time any user will visits the website, the XSS triggers and attacker can steal the cookie according to the crafted payload.

    Source:Hemant Patidar
    Published:30 Dec 2020
    6.1
    Medium

    CVE-2020-29204

    Last Modified: 21 Nov 2024

    XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.

    Published:27 Dec 2020
    5.3
    Medium

    CVE-2020-29156

    Last Modified: 21 Nov 2024

    The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.

    Published:27 Dec 2020
    8.6
    High

    CVE-2020-29134

    Last Modified: 21 Nov 2024

    The TOTVS Fluig platform allows path traversal through the parameter "file = .. /" encoded in base64. This affects all versions Fluig Lake 1.7.0, Fluig 1.6.5 and Fluig 1.6.4

    Published:5 Mar 2021
    4.8
    Medium

    CVE-2020-29070

    Last Modified: 21 Nov 2024

    osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of newsletters.

    Published:25 Nov 2020
    9.8
    Critical

    CVE-2020-29007

    Last Modified: 6 Feb 2025

    The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted {{Image data to generate musical scores containing malicious code.

    Published:15 Apr 2023
    5.3
    Medium

    CVE-2020-28978

    Last Modified: 4 Dec 2020

    The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/tree.php?subdomain=SSRF.

    Source:Pankaj Verma
    Published:30 Nov 2020
    5.3
    Medium

    CVE-2020-28977

    Last Modified: 4 Dec 2020

    The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/get.php?subdomain=SSRF.

    Source:Pankaj Verma
    Published:30 Nov 2020
    5.3
    Medium

    CVE-2020-28976

    Last Modified: 4 Dec 2020

    The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/detail.php?subdomain=SSRF.

    Source:Pankaj Verma
    Published:30 Nov 2020
    7.8
    High

    CVE-2020-28948

    Last Modified: 21 Nov 2024

    Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

    Published:19 Nov 2020
    9.8
    Critical

    CVE-2020-28926

    Last Modified: 21 Nov 2024

    ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug resulting in a buffer overflow in calls to memcpy/memmove.

    Published:30 Nov 2020