7.8
    High

    CVE-2020-24088

    Last Modified: 21 Nov 2024

    An issue was discovered in MmMapIoSpace routine in Foxconn Live Update Utility 2.1.6.26, allows local attackers to escalate privileges.

    Published:11 Sept 2023
    8.8
    High

    CVE-2020-24033

    Last Modified: 21 Nov 2024

    An issue was discovered in fs.com S3900 24T4S 1.7.0 and earlier. The form does not have an authentication or token authentication mechanism that allows remote attackers to forge requests on behalf of a site administrator to change all settings including deleting users, creating new users with escalated privileges.

    Published:22 Oct 2020
    9.8
    Critical

    CVE-2020-24032

    Last Modified: 21 Nov 2024

    tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharacters in a timezone.

    Published:18 Aug 2020
    9.8
    Critical

    CVE-2020-24030

    Last Modified: 14 Oct 2025

    ForLogic Qualiex v1 and v3 has weak token expiration. This allows remote unauthenticated privilege escalation and access to sensitive data via token reuse. NOTE: as of 2025-10-14, the Supplier's perspective is that this is "not exploitable in the current implementation. Tokens are properly expired, invalidated, and bound to session context. Attempts to alter the token payload to extend its validity do not affect server-side validation."

    Published:2 Sept 2020
    9.8
    Critical

    CVE-2020-24029

    Last Modified: 14 Oct 2025

    Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can be accessed via a simple request. NOTE: as of 2025-10-14, the Supplier's perspective is that this is "corrected in all maintained versions. Password reset requests are validated against registered user emails and require a valid, short-lived token."

    Published:2 Sept 2020
    8.8
    High

    CVE-2020-24028

    Last Modified: 14 Oct 2025

    ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates. NOTE: as of 2025-10-14, the Supplier's perspective is that this "does not allow administrative privilege gain. Authorization is enforced server-side, restricting actions to the user’s own permission scope."

    Published:2 Sept 2020
    7.5
    High

    CVE-2020-23972

    Last Modified: 1 Dec 2020

    In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.

    Source:ThelastVvV
    Published:27 Aug 2020
    7.8
    High

    CVE-2020-23968

    Last Modified: 21 Nov 2024

    Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\Ilex\S&G\Logs\000-sngWSService1.log.

    Published:10 Nov 2020
    9.8
    Critical

    CVE-2020-23935

    Last Modified: 9 Dec 2021

    Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".

    Source:Enes Özeser
    Published:20 Aug 2020
    8.8
    High

    CVE-2020-23934

    Last Modified: 26 Oct 2020

    An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager" section.

    Source:Enes Özeser
    Published:18 Aug 2020
    6.1
    Medium

    CVE-2020-23839

    Last Modified: 29 Oct 2021

    A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote attackers to execute JavaScript code in the client's browser and harvest login credentials after a client clicks a link, enters credentials, and submits the login form.

    Source:boku
    Published:1 Sept 2020
    6.4
    Medium

    CVE-2020-23835

    Last Modified: 15 Sept 2020

    A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Management System v1.0 allows remote attackers to harvest keys pressed by an unauthenticated victim who clicks on a malicious URL and begins typing.

    Source:boku
    Published:1 Sept 2020
    6.5
    Medium

    CVE-2020-23593

    Last Modified: 29 Apr 2025

    A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2, Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross site request forgery (CSRF) attack to enable syslog mode through ' /mgm_log_cfg.asp.' The system starts to log events, 'Remote' mode or 'Both' mode on "Syslog -- Configuration page" logs events and sends to remote syslog server IP and Port.

    Published:23 Nov 2022
    8.8
    High

    CVE-2020-23592

    Last Modified: 29 Apr 2025

    A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to Reset ONU to Factory Default through ' /mgm_dev_reset.asp.' Resetting to default leads to Escalation of Privileges by logging-in with default credentials.

    Published:23 Nov 2022
    9.8
    Critical

    CVE-2020-23591

    Last Modified: 29 Apr 2025

    A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker to upload arbitrary files through " /mgm_dev_upgrade.asp " which can "delete every file for Denial of Service (using 'rm -rf *.*' in the code), reverse connection (using '.asp' webshell), backdoor.

    Published:23 Nov 2022
    6.5
    Medium

    CVE-2020-23590

    Last Modified: 29 Apr 2025

    A vulnerability in Optilink OP-XT71000N Hardware version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated remote attacker to conduct a cross-site request forgery (CSRF) attack to change the Password for "WLAN SSID" through "wlwpa.asp".

    Published:23 Nov 2022
    6.5
    Medium

    CVE-2020-23589

    Last Modified: 29 Apr 2025

    A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to cause a Denial of Service by Rebooting the router through " /mgm_dev_reboot.asp."

    Published:23 Nov 2022
    4.3
    Medium

    CVE-2020-23588

    Last Modified: 25 Apr 2025

    A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to "Enable or Disable Ports" and to "Change port number" through " /rmtacc.asp ".

    Published:23 Nov 2022
    3.1
    Low

    CVE-2020-23587

    Last Modified: 25 Apr 2025

    A vulnerability found in the OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to men in the middle attack by adding New Routes in RoutingConfiguration on " /routing.asp ".

    Published:23 Nov 2022
    4.3
    Medium

    CVE-2020-23586

    Last Modified: 25 Apr 2025

    A vulnerability found in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to Add Network Traffic Control Type Rule.

    Published:23 Nov 2022
    8.8
    High

    CVE-2020-23585

    Last Modified: 25 Apr 2025

    A remote attacker can conduct a cross-site request forgery (CSRF) attack on OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028. The vulnerability is due to insufficient CSRF protections for the "mgm_config_file.asp" because of which attacker can create a crafted "csrf form" which sends " malicious xml data" to "/boaform/admin/formMgmConfigUpload". the exploit allows attacker to "gain full privileges" and to "fully compromise of router & network".

    Published:23 Nov 2022
    9.8
    Critical

    CVE-2020-23584

    Last Modified: 25 Apr 2025

    Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in the "PingTest" parameter that leads to command execution.

    Published:23 Nov 2022
    9.8
    Critical

    CVE-2020-23583

    Last Modified: 25 Apr 2025

    OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker can successfully trigger the COMMAND and can compromise full system.

    Published:23 Nov 2022
    6.5
    Medium

    CVE-2020-23582

    Last Modified: 29 Apr 2025

    A vulnerability in the "/admin/wlmultipleap.asp" of optilink OP-XT71000N version: V2.2 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to create Multiple WLAN BSSID.

    Published:21 Nov 2022
    6.8
    Medium

    CVE-2020-23522

    Last Modified: 3 Feb 2021

    Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.

    Source:Noth
    Published:19 Jan 2021
    5.4
    Medium

    CVE-2020-23518

    Last Modified: 4 Mar 2021

    Cross Site Scripting (XSS) vulnerability in UltimateKode Neo Billing - Accounting, Invoicing And CRM Software up to version 3.5 which allows remote attackers to inject arbitrary web script or HTML.

    Source:n1x_
    Published:2 Mar 2021
    8.8
    High

    CVE-2020-23489

    Last Modified: 21 Nov 2024

    The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which leads to certain privilege checks not being in place, and therefore a user can escalate privileges to admin.

    Published:16 Nov 2020
    7.5
    High

    CVE-2020-23349

    Last Modified: 21 Nov 2024

    An intent redirection issue was doscovered in Sina Weibo Android SDK 4.2.7 (com.sina.weibo.sdk.share.WbShareTransActivity), any unexported Activities could be started by the com.sina.weibo.sdk.share.WbShareTransActivity.

    Published:5 Apr 2022
    8.8
    High

    CVE-2020-23342

    Last Modified: 21 Jan 2021

    A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.

    Source:Ninad Mishra
    Published:19 Jan 2021
    8.8
    High

    CVE-2020-23160

    Last Modified: 21 Nov 2024

    Remote code execution in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to arbitrary commands as root on the devices.

    Published:22 Jan 2021
    8.8
    High

    CVE-2020-23127

    Last Modified: 21 Nov 2024

    Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.

    Published:5 May 2021
    4.8
    Medium

    CVE-2020-22841

    Last Modified: 10 Feb 2021

    Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.

    Source:Soham Bakore
    Published:9 Feb 2021
    9.8
    Critical

    CVE-2020-21378

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.

    Published:21 Dec 2020
    7.5
    High

    CVE-2020-21365

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations.

    Published:15 Aug 2022
    7.2
    High

    CVE-2020-20969

    Last Modified: 3 Dec 2025

    File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.

    Source:CodeSecLab
    Published:20 Jun 2023
    9.8
    Critical

    CVE-2020-20277

    Last Modified: 2 Aug 2022

    There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server versions 2.7 to 2.10 due to improper implementation of a chroot jail in common.c's compose_abspath function that can be abused to read or write to arbitrary files on the filesystem, leak process memory, or potentially lead to remote code execution.

    Source:Aaron Esau
    Published:18 Dec 2020
    6.1
    Medium

    CVE-2020-20142

    Last Modified: 21 Dec 2020

    Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table & Charts 2.7.17.

    Source:Marco Nappi
    Published:17 Dec 2020
    6.1
    Medium

    CVE-2020-20141

    Last Modified: 21 Dec 2020

    Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.

    Source:Marco Nappi
    Published:17 Dec 2020
    6.1
    Medium

    CVE-2020-20140

    Last Modified: 21 Dec 2020

    Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17.

    Source:Marco Nappi
    Published:17 Dec 2020
    6.1
    Medium

    CVE-2020-20139

    Last Modified: 21 Dec 2020

    Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.

    Source:Marco Nappi
    Published:17 Dec 2020
    6.5
    Medium

    CVE-2020-20093

    Last Modified: 21 Nov 2024

    The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.

    Published:23 Mar 2022
    5.4
    Medium

    CVE-2020-19587

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote attackers to run arbitrary code via MIAdminStyles.i4 Admin UI.

    Published:14 Sept 2022
    9
    Critical

    CVE-2020-19586

    Last Modified: 21 Nov 2024

    Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI.

    Published:14 Sept 2022
    7.5
    High

    CVE-2020-19360

    Last Modified: 21 Nov 2024

    Local file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a file, which can lead to sensitive information disclosure.

    Published:20 Jan 2021
    5.4
    Medium

    CVE-2020-18724

    Last Modified: 8 Feb 2021

    Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening a contact list.

    Source:Kailash Bohara
    Published:3 Feb 2021
    5.4
    Medium

    CVE-2020-18723

    Last Modified: 8 Feb 2021

    Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side while forwarding an email to perform potentially malicious activities.

    Source:Kailash Bohara
    Published:3 Feb 2021
    9.8
    Critical

    CVE-2020-18662

    Last Modified: 13 Apr 2025

    SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.

    Source:CodeSecLab
    Published:24 Jun 2021
    8.8
    High

    CVE-2020-18326

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.

    Published:4 Mar 2022
    6.1
    Medium

    CVE-2020-18325

    Last Modified: 21 Nov 2024

    Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.

    Published:4 Mar 2022
    6.1
    Medium

    CVE-2020-18324

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.

    Published:4 Mar 2022