7.5
    High

    CVE-2020-11650

    Last Modified: 21 Nov 2024

    An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a denial of service. The login authentication component has no limits on the length of an authentication message or the rate at which such messages are sent.

    Published:8 Apr 2020
    8.1
    High

    CVE-2020-11620

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).

    Published:7 Apr 2020
    8.1
    High

    CVE-2020-11619

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).

    Published:6 Apr 2020
    7.5
    High

    CVE-2020-11579

    Last Modified: 21 Nov 2024

    An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unauthenticated attacker to disclose local files on hosts running PHP before 7.2.16, or on hosts where the MySQL ALLOW LOCAL DATA INFILE option is enabled.

    Published:3 Sept 2020
    7.8
    High

    CVE-2020-11560

    Last Modified: 23 Jun 2023

    NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.

    Source:Tejas Pingulkar
    Published:7 Apr 2020
    5.3
    Medium

    CVE-2020-11547

    Last Modified: 21 Nov 2024

    PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by type=probes to login.htm or index.htm.

    Published:4 Apr 2020
    9.8
    Critical

    CVE-2020-11546

    Last Modified: 21 Nov 2024

    SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.

    Published:14 Jul 2020
    8.1
    High

    CVE-2020-11539

    Last Modified: 21 Nov 2024

    An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE security level) The data being transmitted over the air is not encrypted. Adding to this, the data being sent to the smart band doesn't have any authentication or signature verification. Thus, any attacker can control a parameter of the device.

    Published:22 Apr 2020
    9.8
    Critical

    CVE-2020-11530

    Last Modified: 13 May 2020

    A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter supplied to get_script/index.php, and allows an attacker to execute arbitrary SQL queries in the context of the WP database user.

    Source:SunCSR
    Published:8 May 2020
    7.8
    High

    CVE-2020-11519

    Last Modified: 21 Nov 2024

    The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to read or write to physical disc sectors via a \\.\SecureDocDevice handle. Exploiting this vulnerability results in privileged code execution.

    Published:22 Jun 2020
    8.1
    High

    CVE-2020-11493

    Last Modified: 21 Nov 2024

    In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without concern for a crafted XObject.

    Published:4 Sept 2020
    7.8
    High

    CVE-2020-11492

    Last Modified: 21 Nov 2024

    An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe prior to starting Docker with the same name, this attacker can intercept a connection attempt from Docker Service (which runs as SYSTEM), and then impersonate their privileges.

    Published:5 Jun 2020
    5.4
    Medium

    CVE-2020-11457

    Last Modified: 7 Apr 2020

    pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user.

    Source:Matthew Aberegg
    Published:1 Apr 2020
    5.4
    Medium

    CVE-2020-11456

    Last Modified: 6 Apr 2020

    LimeSurvey before 4.1.12+200324 has stored XSS in application/views/admin/surveysgroups/surveySettings.php and application/models/SurveysGroups.php (aka survey groups).

    Source:Matthew Aberegg
    Published:1 Apr 2020
    9.8
    Critical

    CVE-2020-11455

    Last Modified: 17 Mar 2021

    LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php.

    Source:Matthew Aberegg
    Published:1 Apr 2020
    8.8
    High

    CVE-2020-11444

    Last Modified: 21 Nov 2024

    Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.

    Published:2 Apr 2020
    7
    High

    CVE-2020-11179

    Last Modified: 21 Nov 2024

    Arbitrary read and write to kernel addresses by temporarily overwriting ring buffer pointer and creating a race condition. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published:21 Jan 2021
    8.8
    High

    CVE-2020-11113

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).

    Published:28 Mar 2020
    8.8
    High

    CVE-2020-11112

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).

    Published:25 Mar 2020
    8.8
    High

    CVE-2020-11111

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).

    Published:24 Mar 2020
    5.4
    Medium

    CVE-2020-11110

    Last Modified: 21 Nov 2024

    Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.

    Published:1 Apr 2020
    8.8
    High

    CVE-2020-11108

    Last Modified: 27 May 2021

    The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to escalate privileges to root.) The code error is in gravity_DownloadBlocklistFromUrl in gravity.sh.

    Source:Photubias
    Published:11 May 2020
    8.8
    High

    CVE-2020-11107

    Last Modified: 1 Aug 2022

    An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution.

    Source:Salman Asad
    Published:2 Apr 2020
    3.5
    Low

    CVE-2020-11097

    Last Modified: 21 Nov 2024

    In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.

    Published:22 Jun 2020
    7.5
    High

    CVE-2020-11076

    Last Modified: 21 Nov 2024

    In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.

    Published:21 May 2020
    7.4
    High

    CVE-2020-11060

    Last Modified: 14 Jun 2021

    In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited by an attacker without a valid account by using a CSRF. Due to the difficulty of the exploitation, the attack is only conceivable by an account having Maintenance privileges and the right to add WIFI networks. This is fixed in version 9.4.6.

    Source:Brian Peters
    Published:12 May 2020
    6.1
    Medium

    CVE-2020-11027

    Last Modified: 19 Jun 2023

    In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

    Source:Amirhossein Bahramizadeh
    Published:30 Apr 2020
    6.9
    Medium

    CVE-2020-11023

    Last Modified: 14 Apr 2021

    In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

    Source:Central InfoSec
    Published:29 Apr 2020
    6.9
    Medium

    CVE-2020-11022

    Last Modified: 14 Apr 2021

    In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

    Source:Central InfoSec
    Published:23 Apr 2020
    4.3
    Medium

    CVE-2020-11019

    Last Modified: 21 Nov 2024

    In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOG_TRACE", a possible crash of application could occur due to a read of an invalid array index. Data could be printed as string to local terminal. This has been fixed in 2.1.0.

    Published:9 Apr 2020
    9.8
    Critical

    CVE-2020-10987

    Last Modified: 7 Nov 2025

    The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.

    Published:13 Jul 2020
    5.5
    Medium

    CVE-2020-10977

    Last Modified: 21 Nov 2024

    GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.

    Published:8 Apr 2020
    8.8
    High

    CVE-2020-10969

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.

    Published:3 Mar 2020
    8.8
    High

    CVE-2020-10968

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).

    Published:22 Mar 2020
    7.2
    High

    CVE-2020-10963

    Last Modified: 27 Nov 2020

    FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/file_upload image upload with PHP content within a GIF image that has the .php extension. NOTE: this product is discontinued.

    Source:Xavi Beltran
    Published:25 Mar 2020
    9.8
    Critical

    CVE-2020-10915

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HandshakeResult method. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-10401.

    Published:22 Apr 2020
    8.8
    High

    CVE-2020-10884

    Last Modified: 16 Apr 2020

    This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tdpServer service, which listens on UDP port 20002 by default. This issue results from the use of hard-coded encryption key. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-9652.

    Source:Metasploit
    Published:25 Mar 2020
    7.8
    High

    CVE-2020-10883

    Last Modified: 16 Apr 2020

    This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the file system. The issue lies in the lack of proper permissions set on the file system. An attacker can leverage this vulnerability to escalate privileges. Was ZDI-CAN-9651.

    Source:Metasploit
    Published:25 Mar 2020
    8.8
    High

    CVE-2020-10882

    Last Modified: 16 Apr 2020

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tdpServer service, which listens on UDP port 20002 by default. When parsing the slave_mac parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the root user. Was ZDI-CAN-9650.

    Source:Metasploit
    Published:25 Mar 2020
    9.8
    Critical

    CVE-2020-10879

    Last Modified: 26 Mar 2020

    rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed directly to the exec function without being escaped.

    Source:Matthew Aberegg
    Published:23 Mar 2020
    5.3
    Medium

    CVE-2020-10770

    Last Modified: 13 Oct 2021

    A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.

    Source:Mayank Deshmukh
    Published:26 Nov 2020
    6
    Medium

    CVE-2020-10759

    Last Modified: 21 Nov 2024

    A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.

    Published:5 Jun 2020
    7.8
    High

    CVE-2020-10757

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.

    Published:4 Jun 2020
    6
    Medium

    CVE-2020-10749

    Last Modified: 21 Nov 2024

    A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

    Published:1 Jun 2020
    8.2
    High

    CVE-2020-10713

    Last Modified: 21 Nov 2024

    A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows the bypass of Secure Boot protections. In order to load an untrusted or modified kernel, an attacker would first need to establish access to the system such as gaining physical access, obtain the ability to alter a pxe-boot network, or have remote access to a networked system with root access. With this access, an attacker could then craft a string to cause a buffer overflow by injecting a malicious payload that leads to arbitrary code execution within GRUB. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published:29 Jul 2020
    8.8
    High

    CVE-2020-10673

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).

    Published:18 Mar 2020
    6.7
    Medium

    CVE-2020-10665

    Last Modified: 21 Nov 2024

    Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnostics with Administrator privileges, leading to arbitrary DACL permissions overwrites and arbitrary file writes. This affects Docker Desktop Enterprise before 2.1.0.9, Docker Desktop for Windows Stable before 2.2.0.4, and Docker Desktop for Windows Edge before 2.2.2.0.

    Published:18 Mar 2020
    7.5
    High

    CVE-2020-10663

    Last Modified: 21 Nov 2024

    The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.

    Published:19 Mar 2020
    5.4
    Medium

    CVE-2020-10596

    Last Modified: 2 Jun 2020

    OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section.

    Source:Kailash Bohara
    Published:17 Mar 2020
    9.8
    Critical

    CVE-2020-10567

    Last Modified: 21 Nov 2024

    An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent. This makes it possible to execute PHP code if a legitimate JPEG image contains this code in the EXIF data, and the .php extension is used in the name parameter. (A potential fast patch is to disable the save_img action in the config file.)

    Published:14 Mar 2020