9.8
    Critical

    CVE-2020-13927

    Last Modified: 2 Jun 2021

    The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and is documented at https://airflow.apache.org/docs/1.10.11/security.html#api-authentication. Note this change fixes it for new installs but existing users need to change their config to default `[api]auth_backend = airflow.api.auth.backend.deny_all` as mentioned in the Updating Guide: https://github.com/apache/airflow/blob/1.10.11/UPDATING.md#experimental-api-will-deny-all-request-by-default

    Source:Pepe Berba
    Published:10 Nov 2020
    9.8
    Critical

    CVE-2020-13925

    Last Modified: 21 Nov 2024

    Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; while the reported API misses necessary input validation, which causes the hackers to have the possibility to execute OS command remotely. Users of all previous versions after 2.3 should upgrade to 3.1.0.

    Published:14 Jul 2020
    5.4
    Medium

    CVE-2020-13889

    Last Modified: 21 Nov 2024

    showAlert() in the administration panel in Bludit 3.12.0 allows XSS.

    Published:6 Jun 2020
    5.3
    Medium

    CVE-2020-13886

    Last Modified: 21 Nov 2024

    Intelbras TIP 200 60.61.75.15, TIP 200 LITE 60.61.75.15, and TIP 300 65.61.75.22 devices allow cgi-bin/cgiServer.exx?page=../ Directory Traversal.

    Published:26 Nov 2020
    7.8
    High

    CVE-2020-13885

    Last Modified: 21 Nov 2024

    Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the application.

    Published:8 Jun 2020
    7.8
    High

    CVE-2020-13884

    Last Modified: 21 Nov 2024

    Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the uninstallation of the application.

    Published:8 Jun 2020
    7.8
    High

    CVE-2020-13866

    Last Modified: 10 Jun 2020

    WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges by replacing an executable file with a Trojan horse.

    Source:hyp3rlinx
    Published:8 Jun 2020
    8.8
    High

    CVE-2020-13851

    Last Modified: 21 Nov 2024

    Artica Pandora FMS 7.44 allows remote command execution via the events feature.

    Published:11 Jun 2020
    7.4
    High

    CVE-2020-13777

    Last Modified: 21 Nov 2024

    GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation, the TLS server always uses wrong data in place of an encryption key derived from an application.

    Published:3 Jun 2020
    9.8
    Critical

    CVE-2020-13768

    Last Modified: 21 Nov 2024

    In MiniShare before 1.4.2, there is a stack-based buffer overflow via an HTTP PUT request, which allows an attacker to achieve arbitrary code execution, a similar issue to CVE-2018-19861, CVE-2018-19862, and CVE-2019-17601. NOTE: this product is discontinued.

    Published:4 Jun 2020
    9.8
    Critical

    CVE-2020-13756

    Last Modified: 3 Nov 2025

    Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker.

    Published:3 Jun 2020
    8.8
    High

    CVE-2020-13699

    Last Modified: 21 Nov 2024

    TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10: --play URL. An attacker could force a victim to send an NTLM authentication request and either relay the request or capture the hash for offline password cracking. This affects teamviewer10, teamviewer8, teamviewerapi, tvchat1, tvcontrol1, tvfiletransfer1, tvjoinv8, tvpresent1, tvsendfile1, tvsqcustomer1, tvsqsupport1, tvvideocall1, and tvvpn1. The issue is fixed in 8.0.258861, 9.0.258860, 10.0.258873, 11.0.258870, 12.0.258869, 13.2.36220, 14.2.56676, 14.7.48350, and 15.8.3.

    Published:29 Jul 2020
    9.8
    Critical

    CVE-2020-13693

    Last Modified: 1 Jun 2020

    An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.

    Source:Raphael Karger
    Published:28 May 2020
    8.8
    High

    CVE-2020-13671

    Last Modified: 3 Nov 2025

    Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

    Published:20 Nov 2020
    7.5
    High

    CVE-2020-13654

    Last Modified: 21 Nov 2024

    XWiki Platform before 12.8 mishandles escaping in the property displayer.

    Published:31 Dec 2020
    9.8
    Critical

    CVE-2020-13640

    Last Modified: 21 Nov 2024

    A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.)

    Published:18 Jun 2020
    8.8
    High

    CVE-2020-13519

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c402088 functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) can cause increased privileges. An attacker can send a malicious IRP to trigger this vulnerability.

    Published:18 Dec 2020
    Unknown

    CVE-2020-13457

    https://github.com/alt3kx/CVE-2020-13457

    8.8
    High

    CVE-2020-13448

    Last Modified: 1 Jun 2020

    QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.

    Source:s1gh
    Published:1 Jun 2020
    6.5
    Medium

    CVE-2020-13424

    Last Modified: 21 Nov 2024

    The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure.

    Published:23 May 2020
    7.5
    High

    CVE-2020-13405

    Last Modified: 21 Nov 2024

    userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.

    Published:16 Jul 2020
    6
    Medium

    CVE-2020-13401

    Last Modified: 21 Nov 2024

    An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.

    Published:1 Jun 2020
    8.3
    High

    CVE-2020-13398

    Last Modified: 21 Nov 2024

    An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.

    Published:22 May 2020
    8.2
    High

    CVE-2020-13379

    Last Modified: 6 Jul 2020

    The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

    Source:mostwanted002
    Published:3 Jun 2020
    6.3
    Medium

    CVE-2020-13277

    Last Modified: 21 Nov 2024

    An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5

    Published:19 Jun 2020
    6.1
    Medium

    CVE-2020-13260

    Last Modified: 4 Dec 2020

    A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated attacker to upload a JavaScript file, with a stored XSS payload, that will remain stored in the system as an OVPN file in Configuration-Services-Security-OpenVPN-Config or as the static key file in Configuration-Services-Security-OpenVPN-Static Keys. This payload will execute each time a user opens an affected web page. This could be exploited in conjunction with CVE-2020-13259.

    Source:Jonatan Schor
    Published:17 Sept 2020
    8.8
    High

    CVE-2020-13259

    Last Modified: 4 Dec 2020

    A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. This could be exploited in conjunction with CVE-2020-13260.

    Source:Jonatan Schor
    Published:16 Sept 2020
    5.9
    Medium

    CVE-2020-13254

    Last Modified: 21 Nov 2024

    An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.

    Published:3 Jun 2020
    6.1
    Medium

    CVE-2020-13228

    Last Modified: 16 Jun 2020

    An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter.

    Source:Luca Epifanio
    Published:2 Jun 2020
    9.8
    Critical

    CVE-2020-13166

    Last Modified: 25 May 2020

    The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers' installations) in web.config, and can be used to send serialized ASP code.

    Source:Metasploit
    Published:19 May 2020
    7
    High

    CVE-2020-13162

    Last Modified: 5 May 2025

    A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows (which runs as NT AUTHORITY/SYSTEM) allows unprivileged users to run a Microsoft Installer executable with elevated privileges.

    Published:16 Jun 2020
    9.8
    Critical

    CVE-2020-13160

    Last Modified: 20 Dec 2021

    AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.

    Source:scryh
    Published:9 Jun 2020
    9.8
    Critical

    CVE-2020-13159

    Last Modified: 21 Nov 2024

    Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Alias field. NOTE: this may overlap CVE-2020-10818.

    Published:22 Jun 2020
    7.5
    High

    CVE-2020-13158

    Last Modified: 21 Nov 2024

    Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter.

    Published:22 Jun 2020
    5.5
    Medium

    CVE-2020-13152

    Last Modified: 5 Nov 2020

    A remote user can create a specially crafted M3U file, media playlist file that when loaded by the target user, will trigger a memory leak, whereby Amarok 2.8.0 continue to waste resources over time, eventually allows attackers to cause a denial of service.

    Source:FishballAndMeatball
    Published:20 May 2020
    9.8
    Critical

    CVE-2020-13151

    Last Modified: 17 Nov 2020

    Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query. It attempts to restrict code execution by disabling os.execute() calls, but this is insufficient. Anyone with network access can use a crafted UDF to execute arbitrary OS commands on all nodes of the cluster at the permission level of the user running the Aerospike service.

    Source:Matt S
    Published:5 Aug 2020
    8.8
    High

    CVE-2020-13144

    Last Modified: 21 May 2020

    Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Python evaluated code" screen, edit the problem, and execute Python code. This leads to arbitrary code execution.

    Source:Daniel Monzón
    Published:18 May 2020
    9.8
    Critical

    CVE-2020-13118

    Last Modified: 18 May 2020

    An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter community.

    Source:jul10l1r4
    Published:16 May 2020
    5.4
    Medium

    CVE-2020-13094

    Last Modified: 21 Nov 2024

    Dolibarr before 11.0.4 allows XSS.

    Published:18 May 2020
    7.8
    High

    CVE-2020-12928

    Last Modified: 21 Nov 2024

    A vulnerability in a dynamically loaded AMD driver in AMD Ryzen Master V15 may allow any authenticated user to escalate privileges to NT authority system.

    Published:13 Oct 2020
    5.4
    Medium

    CVE-2020-12882

    Last Modified: 19 May 2020

    Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a Teaching Fellow.

    Source:humblelad
    Published:15 May 2020
    9.8
    Critical

    CVE-2020-12856

    Last Modified: 21 Nov 2024

    OpenTrace, as used in COVIDSafe through v1.0.17, TraceTogether, ABTraceTogether, and other applications on iOS and Android, allows remote attackers to conduct long-term re-identification attacks and possibly have unspecified other impact, because of how Bluetooth is used.

    Published:18 May 2020
    9.8
    Critical

    CVE-2020-12828

    Last Modified: 21 Nov 2024

    An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations over a socket bound to localhost. Binding to the socket and providing a path where a malicious executable file resides leads to executing the malicious executable file with SYSTEM privileges.

    Published:21 May 2020
    9.8
    Critical

    CVE-2020-12800

    Last Modified: 21 Nov 2024

    The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.

    Published:8 Jun 2020
    9.8
    Critical

    CVE-2020-12753

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Arbitrary code execution can occur via the bootloader because of an EL1/EL3 coldboot vulnerability involving raw_resources. The LG ID is LVE-SMP-200006 (May 2020).

    Published:11 May 2020
    6.5
    Medium

    CVE-2020-12717

    Last Modified: 21 Nov 2024

    The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere with COVID-19 contact tracing, via a Bluetooth advertisement containing manufacturer data that is too short. This occurs because of an erroneous OpenTrace manuData.subdata call. The ABTraceTogether (Alberta), ProteGO (Poland), and TraceTogether (Singapore) apps were also affected.

    Published:14 May 2020
    7.5
    High

    CVE-2020-12712

    Last Modified: 15 Jun 2020

    A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 and 1.13 allows attackers to decrypt the user/password that is optionally stored with a user's profile.

    Source:Sander Ubink
    Published:11 Jun 2020
    6.1
    Medium

    CVE-2020-12707

    Last Modified: 11 May 2020

    An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elements. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT elements.

    Source:SunCSR
    Published:7 May 2020
    5.4
    Medium

    CVE-2020-12706

    Last Modified: 11 May 2020

    Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_admin.php

    Source:SunCSR
    Published:7 May 2020
    6.1
    Medium

    CVE-2020-12704

    Last Modified: 11 May 2020

    UliCMS before 2020.2 has PageController stored XSS.

    Source:SunCSR
    Published:7 May 2020