7.5
    High

    CVE-2020-28874

    Last Modified: 21 Nov 2024

    reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).

    Published:21 Jan 2021
    8.8
    High

    CVE-2020-28688

    Last Modified: 2 Dec 2020

    The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.

    Source:Shahrukh Iqbal Mirza
    Published:17 Nov 2020
    8.8
    High

    CVE-2020-28687

    Last Modified: 2 Dec 2020

    The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.

    Source:Shahrukh Iqbal Mirza
    Published:17 Nov 2020
    9.8
    Critical

    CVE-2020-28653

    Last Modified: 21 Nov 2024

    Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.

    Published:3 Feb 2021
    5.4
    Medium

    CVE-2020-28647

    Last Modified: 21 Nov 2024

    In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim's browser (XSS).

    Published:17 Nov 2020
    8.1
    High

    CVE-2020-28502

    Last Modified: 21 Nov 2024

    This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into xhr.send could result in arbitrary code being injected and run.

    Published:5 Mar 2021
    7.5
    High

    CVE-2020-28491

    Last Modified: 21 Nov 2024

    This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.

    Published:18 Feb 2021
    Low

    CVE-2020-28488

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published:22 Jan 2021
    7.5
    High

    CVE-2020-28478

    Last Modified: 21 Nov 2024

    This affects the package gsap before 3.6.0.

    Published:19 Jan 2021
    7.3
    High

    CVE-2020-28458

    Last Modified: 21 Nov 2024

    All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806.

    Published:25 Oct 2020
    6.1
    Medium

    CVE-2020-28415

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauthenticated attacker is able to execute arbitrary HTML code via crafted url (different vector than CVE-2020-28414).

    Published:12 Nov 2020
    6.1
    Medium

    CVE-2020-28414

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauthenticated attacker is able to execute arbitrary HTML code via crafted url (different vector than CVE-2020-28415).

    Published:12 Nov 2020
    5.3
    Medium

    CVE-2020-28413

    Last Modified: 4 Jan 2021

    In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP.

    Source:EthicalHCOP
    Published:30 Dec 2020
    6.1
    Medium

    CVE-2020-28351

    Last Modified: 10 Nov 2020

    The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack (via the PATH_INFO to index.php) due to insufficient validation for the time_zone object in the HOME_MEETING& page.

    Source:Joe Helle
    Published:9 Nov 2020
    7.2
    High

    CVE-2020-28337

    Last Modified: 10 May 2021

    A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload a maliciously constructed ZIP file with file paths including relative paths (i.e., ../../), move this file into the backup directory, and execute a restore on this file.

    Source:sl1nki
    Published:15 Feb 2021
    8.8
    High

    CVE-2020-28328

    Last Modified: 9 Nov 2020

    SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.

    Source:M. Cory Billington
    Published:6 Nov 2020
    6.1
    Medium

    CVE-2020-28249

    Last Modified: 9 Nov 2020

    Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note.

    Source:Philip Holbrook
    Published:6 Nov 2020
    7.8
    High

    CVE-2020-28243

    Last Modified: 21 Nov 2024

    An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.

    Published:25 Feb 2021
    7
    High

    CVE-2020-28169

    Last Modified: 5 Jan 2021

    The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITY\SYSTEM.

    Source:Adrian Bondocea
    Published:24 Dec 2020
    Unknown

    CVE-2020-28148

    https://github.com/fengchenzxc/CVE-2020-28148

    6.1
    Medium

    CVE-2020-28092

    Last Modified: 19 Nov 2020

    PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&status=0&id=,?g=Team&m=Task&a=my&status=1&id=,?g=Team&m=Task&a=my&status=10&id=

    Source:icekam
    Published:17 Nov 2020
    7.5
    High

    CVE-2020-28091

    Last Modified: 19 Nov 2020

    cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parameter via search.php.

    Source:icekam
    Published:18 Nov 2020
    7.5
    High

    CVE-2020-28054

    Last Modified: 21 Nov 2024

    JamoDat TSMManager Collector version up to 6.5.0.21 is vulnerable to an Authorization Bypass because the Collector component is not properly validating an authenticated session with the Viewer. If the Viewer has been modified (binary patched) and the Bypass Login functionality is being used, an attacker can request every Collector's functionality as if they were a properly logged-in user: administrating connected instances, reviewing logs, editing configurations, accessing the instances' consoles, accessing hardware configurations, etc.Exploiting this vulnerability won't grant an attacker access nor control on remote ISP servers as no credentials is sent with the request.

    Published:19 Nov 2020
    8.1
    High

    CVE-2020-28052

    Last Modified: 12 May 2025

    An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

    Published:18 Dec 2020
    5.3
    Medium

    CVE-2020-28042

    Last Modified: 21 Nov 2024

    ServiceStack before 5.9.2 mishandles JWT signature verification unless an application has a custom ValidateToken function that establishes a valid minimum length for a signature.

    Published:1 Nov 2020
    9.8
    Critical

    CVE-2020-28032

    Last Modified: 21 Nov 2024

    WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

    Published:31 Oct 2020
    9.8
    Critical

    CVE-2020-28022

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer. This occurs when processing name=value pairs within MAIL FROM and RCPT TO commands.

    Published:6 May 2021
    9.8
    Critical

    CVE-2020-28018

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.

    Published:6 May 2021
    9.8
    Critical

    CVE-2020-27976

    Last Modified: 21 Nov 2024

    osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the application. This affects the PHP mail function, and the sendmail -f option.

    Published:28 Oct 2020
    9.8
    Critical

    CVE-2020-27955

    Last Modified: 21 Nov 2024

    Git LFS 2.12.0 allows Remote Code Execution.

    Published:5 Nov 2020
    5.5
    Medium

    CVE-2020-27950

    Last Modified: 27 Oct 2025

    A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to disclose kernel memory.

    Published:8 Dec 2020
    5.5
    Medium

    CVE-2020-27949

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may cause unexpected changes in memory belonging to processes traced by DTrace.

    Published:2 Apr 2021
    6.3
    Medium

    CVE-2020-27935

    Last Modified: 21 Nov 2024

    Multiple issues were addressed with improved logic. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1, watchOS 7.1, tvOS 14.2. A sandboxed process may be able to circumvent sandbox restrictions.

    Published:2 Apr 2021
    7.8
    High

    CVE-2020-27930

    Last Modified: 27 Oct 2025

    A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. Processing a maliciously crafted font may lead to arbitrary code execution.

    Published:8 Dec 2020
    7.8
    High

    CVE-2020-27904

    Last Modified: 21 Nov 2024

    A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. An application may be able to execute arbitrary code with kernel privileges.

    Published:8 Dec 2020
    6.5
    Medium

    CVE-2020-27838

    Last Modified: 21 Nov 2024

    A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same PUBLIC client changed to CONFIDENTIAL later. The highest threat from this vulnerability is to data confidentiality.

    Published:11 Dec 2020
    5.5
    Medium

    CVE-2020-27824

    Last Modified: 21 Nov 2024

    A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to system availability.

    Published:25 Nov 2020
    3.3
    Low

    CVE-2020-27818

    Last Modified: 21 Nov 2024

    A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability.

    Published:8 Dec 2020
    7.8
    High

    CVE-2020-27815

    Last Modified: 21 Nov 2024

    A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

    Published:30 Nov 2020
    7.8
    High

    CVE-2020-27786

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permissions to issue ioctl commands to midi devices could trigger a use-after-free issue. A write to this specific memory while freed and before use causes the flow of execution to change and possibly allow for memory corruption or privilege escalation. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

    Published:2 Dec 2020
    6.8
    Medium

    CVE-2020-27747

    Last Modified: 21 Nov 2024

    An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973).If the user of the system has assigned himself a PIN code for entering from a mobile device using the built-in generator (4 digits), a remote attacker has the opportunity to conduct a brute force attack on this PIN code. As result, remote attacker retrieves all passwords from another systems, available for affected account.

    Published:29 Oct 2020
    7.5
    High

    CVE-2020-27688

    Last Modified: 21 Nov 2024

    RVToolsPasswordEncryption.exe in RVTools 4.0.6 allows users to encrypt passwords to be used in the configuration files. This encryption used a static IV and key, and thus using the Decrypt() method from VISKD.cs from the RVTools.exe executable allows for decrypting the encrypted passwords. The accounts used in the configuration files have access to vSphere instances.

    Published:5 Nov 2020
    7.5
    High

    CVE-2020-27603

    Last Modified: 21 Nov 2024

    BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files.

    Published:21 Oct 2020
    5.4
    Medium

    CVE-2020-27533

    Last Modified: 30 Oct 2020

    A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.

    Source:Noth
    Published:22 Oct 2020
    7.5
    High

    CVE-2020-27423

    Last Modified: 2 Dec 2020

    Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox

    Source:Mufaddal Masalawala
    Published:16 Nov 2020
    9.8
    Critical

    CVE-2020-27422

    Last Modified: 2 Dec 2020

    In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.

    Source:Mufaddal Masalawala
    Published:16 Nov 2020
    5.5
    Medium

    CVE-2020-27368

    Last Modified: 21 Nov 2024

    Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /icons/ directories via GET Parameter.

    Published:14 Jan 2021
    4.3
    Medium

    CVE-2020-27358

    Last Modified: 21 Nov 2024

    An issue was discovered in REDCap 8.11.6 through 9.x before 10. The messenger's CSV feature (that allows users to export their conversation threads as CSV) allows non-privileged users to export one another's conversation threads by changing the thread_id parameter in the request to the endpoint Messenger/messenger_download_csv.php?title=Hey&thread_id={THREAD_ID}.

    Published:31 Oct 2020
    8.8
    High

    CVE-2020-27347

    Last Modified: 21 Nov 2024

    In tmux before version 3.1c the function input_csi_dispatch_sgr_colon() in file input.c contained a stack-based buffer-overflow that can be exploited by terminal output.

    Published:30 Oct 2020
    8
    High

    CVE-2020-27301

    Last Modified: 21 Nov 2024

    A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "AES_UnWRAP" function, when an attacker in Wi-Fi range sends a crafted "Encrypted GTK" value as part of the WPA2 4-way-handshake.

    Published:4 Jun 2021