5.9
    Medium

    CVE-2020-10560

    Last Modified: 21 Nov 2024

    An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserver. This can lead to further compromise. The attacker must conduct a brute-force attack against the SiteKey to insert into a crafted URL for components/OssnComments/ossn_com.php and/or libraries/ossn.lib.upgrade.php.

    Published:30 Mar 2020
    6.5
    Medium

    CVE-2020-10558

    Last Modified: 21 Nov 2024

    The driving interface of Tesla Model 3 vehicles in any release before 2020.4.10 allows Denial of Service to occur due to improper process separation, which allows attackers to disable the speedometer, web browser, climate controls, turn signal visual and sounds, navigation, autopilot notifications, along with other miscellaneous functions from the main screen.

    Published:20 Mar 2020
    7.8
    High

    CVE-2020-10551

    Last Modified: 21 Nov 2024

    QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe. This file is writable by anyone belonging to the NT AUTHORITY\Authenticated Users group, which includes all local and remote users. This can be abused by local attackers to escalate privileges to NT AUTHORITY\SYSTEM by writing a malicious executable to the location of TsService.

    Published:9 Apr 2020
    4.9
    Medium

    CVE-2020-10387

    Last Modified: 16 Mar 2020

    Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server using a dot-dot-slash sequence (../) via the GET parameter file.

    Source:Antonio Cannito
    Published:12 Mar 2020
    7.2
    High

    CVE-2020-10386

    Last Modified: 16 Mar 2020

    admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by uploading a .php file in the admin/js/ directory.

    Source:Antonio Cannito
    Published:12 Mar 2020
    5.4
    Medium

    CVE-2020-10385

    Last Modified: 25 Mar 2020

    A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.

    Source:Jinson Varghese Behanan
    Published:11 Mar 2020
    8.8
    High

    CVE-2020-10239

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.

    Published:16 Mar 2020
    7.5
    High

    CVE-2020-10238

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors.

    Published:16 Mar 2020
    9.8
    Critical

    CVE-2020-10230

    Last Modified: 18 Mar 2020

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parameter.

    Source:Berke YILMAZ
    Published:16 Mar 2020
    8.8
    High

    CVE-2020-10221

    Last Modified: 12 Mar 2020

    lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter.

    Source:Engin Demirbilek
    Published:8 Mar 2020
    9.8
    Critical

    CVE-2020-10220

    Last Modified: 17 Mar 2020

    An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter.

    Source:Metasploit
    Published:7 Mar 2020
    7.2
    High

    CVE-2020-10204

    Last Modified: 21 Nov 2024

    Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.

    Published:1 Apr 2020
    8.8
    High

    CVE-2020-10199

    Last Modified: 8 Jan 2021

    Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

    Source:1F98D
    Published:1 Apr 2020
    9.8
    Critical

    CVE-2020-10189

    Last Modified: 17 Mar 2020

    Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.

    Source:Metasploit
    Published:6 Mar 2020
    8.8
    High

    CVE-2020-10173

    Last Modified: 9 Mar 2020

    Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstrated by shell metacharacters in the pingIpAddress parameter to ping.cgi.

    Source:Raki Ben Hamouda
    Published:5 Mar 2020
    9.8
    Critical

    CVE-2020-10148

    Last Modified: 24 Oct 2025

    The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.

    Published:29 Dec 2020
    5.3
    Medium

    CVE-2020-10136

    Last Modified: 3 Nov 2025

    IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.

    Published:2 Jun 2020
    5.4
    Medium

    CVE-2020-10135

    Last Modified: 21 Nov 2024

    Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key.

    Published:18 May 2020
    6.1
    Medium

    CVE-2020-10132

    Last Modified: 21 Nov 2024

    SearchBlox before Version 9.1 is vulnerable to cross-origin resource sharing misconfiguration.

    Published:6 Sept 2023
    9.8
    Critical

    CVE-2020-10131

    Last Modified: 21 Nov 2024

    SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter.

    Published:6 Sept 2023
    8.8
    High

    CVE-2020-10130

    Last Modified: 21 Nov 2024

    SearchBlox before Version 9.1 is vulnerable to business logic bypass where the user is able to create multiple super admin users in the system.

    Published:6 Sept 2023
    8.8
    High

    CVE-2020-10129

    Last Modified: 21 Nov 2024

    SearchBlox before Version 9.2.1 is vulnerable to Privileged Escalation-Lower user is able to access Admin functionality.

    Published:6 Sept 2023
    5.4
    Medium

    CVE-2020-10128

    Last Modified: 21 Nov 2024

    SearchBlox product with version before 9.2.1 is vulnerable to stored cross-site scripting at multiple user input parameters. In SearchBlox products multiple parameters are not sanitized/validate properly which allows an attacker to inject malicious JavaScript.

    Published:5 Sept 2023
    7.8
    High

    CVE-2020-9992

    Last Modified: 21 Nov 2024

    This issue was addressed by encrypting communications over the network to devices running iOS 14, iPadOS 14, tvOS 14, and watchOS 7. This issue is fixed in iOS 14.0 and iPadOS 14.0, Xcode 12.0. An attacker in a privileged network position may be able to execute arbitrary code on a paired device during a debug session over the network.

    Published:16 Oct 2020
    5.5
    Medium

    CVE-2020-9934

    Last Modified: 23 Oct 2025

    An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may be able to view sensitive user information.

    Published:16 Oct 2020
    6.5
    Medium

    CVE-2020-9922

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra. Processing a maliciously crafted email may lead to writing arbitrary files.

    Published:8 Dec 2020
    8.8
    High

    CVE-2020-9802

    Last Modified: 5 May 2025

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published:9 Jun 2020
    7.8
    High

    CVE-2020-9767

    Last Modified: 21 Nov 2024

    A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was running with elevated privileges to elevate their system privileges as well through use of a malicious DLL. Zoom addressed this issue, which only applies to Windows users, in the 5.0.4 client release.

    Published:14 Aug 2020
    9.6
    Critical

    CVE-2020-9758

    Last Modified: 21 Nov 2024

    An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk). A blind JavaScript injection lies in the name parameter. Triggering this can fetch the username and passwords of the helpdesk employees in the URI. This leads to a privilege escalation, from unauthenticated to user-level access, leading to full account takeover. The attack fetches multiple credentials because they are stored in the database (stored XSS). This affects the mobile/chat URI via the lgn and psswrd parameters.

    Published:9 Mar 2020
    7.8
    High

    CVE-2020-9715

    Last Modified: 14 Apr 2026

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published:19 Aug 2020
    9.8
    Critical

    CVE-2020-9548

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).

    Published:2 Mar 2020
    9.8
    Critical

    CVE-2020-9547

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).

    Published:2 Mar 2020
    9.8
    Critical

    CVE-2020-9546

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).

    Published:2 Mar 2020
    9.8
    Critical

    CVE-2020-9529

    Last Modified: 21 Nov 2024

    Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions of Internet of Things devices, suffers from a privilege escalation vulnerability that allows attackers on the local network to reset the device's administrator password. This affects products marketed under the following brand names: Accfly, Alptop, Anlink, Besdersec, BOAVISION, COOAU, CPVAN, Ctronics, D3D Security, Dericam, Elex System, Elite Security, ENSTER, ePGes, Escam, FLOUREON, GENBOLT, Hongjingtian (HJT), ICAMI, Iegeek, Jecurity, Jennov, KKMoon, LEFTEK, Loosafe, Luowice, Nesuniq, Nettoly, ProElite, QZT, Royallite, SDETER, SV3C, SY2L, Tenvis, ThinkValue, TOMLOV, TPTEK, WGCC, and ZILINK.

    Published:10 Aug 2020
    6.1
    Medium

    CVE-2020-9496

    Last Modified: 29 Oct 2021

    XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03

    Source:Adrián Díaz
    Published:15 Jul 2020
    5.3
    Medium

    CVE-2020-9495

    Last Modified: 21 Nov 2024

    Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute data from the connected LDAP server by providing special values to the login form. With certain characters it is possible to modify the LDAP filter used to query the LDAP users. By measuring the response time for the login request, arbitrary attribute data can be retrieved from LDAP user objects.

    Published:19 Jun 2020
    3.7
    Low

    CVE-2020-9488

    Last Modified: 29 May 2026

    Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

    Published:25 Apr 2020
    7
    High

    CVE-2020-9484

    Last Modified: 25 Aug 2026

    When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.

    Published:20 May 2020
    7.5
    High

    CVE-2020-9483

    Last Modified: 21 Nov 2024

    **Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is a SQL injection vulnerability, which allows to access unpexcted data. Apache SkyWalking 6.0.0 to 6.6.0, 7.0.0 H2/MySQL/TiDB storage implementations don't use the appropriate way to set SQL parameters.

    Published:30 Jun 2020
    9.8
    Critical

    CVE-2020-9480

    Last Modified: 21 Nov 2024

    In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This does not affect Spark clusters using other resource managers (YARN, Mesos, etc).

    Published:22 Jun 2020
    6.5
    Medium

    CVE-2020-9472

    Last Modified: 21 Nov 2024

    Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package functionality.

    Published:16 Mar 2020
    7.8
    High

    CVE-2020-9470

    Last Modified: 21 Nov 2024

    An issue was discovered in Wing FTP Server 6.2.5 before February 2020. Due to insecure permissions when handling session cookies, a local user may view the contents of the session and session_admin directories, which expose active session cookies within the Wing FTP HTTP interface and administration panel. These cookies may be used to hijack user and administrative sessions, including the ability to execute Lua commands as root within the administration panel.

    Published:7 Mar 2020
    5.4
    Medium

    CVE-2020-9467

    Last Modified: 16 Sept 2020

    Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.

    Source:Iridium
    Published:26 Mar 2020
    5.4
    Medium

    CVE-2020-9461

    Last Modified: 21 Nov 2024

    Octech Oempro 4.7 through 4.11 allow stored XSS by an authenticated user. The FolderName parameter of the Media.CreateFolder command is vulnerable.

    Published:14 Apr 2020
    5.4
    Medium

    CVE-2020-9460

    Last Modified: 21 Nov 2024

    Octech Oempro 4.7 through 4.11 allow XSS by an authenticated user. The parameter CampaignName in Campaign.Create is vulnerable.

    Published:14 Apr 2020
    7.8
    High

    CVE-2020-9442

    Last Modified: 21 Nov 2024

    OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to gain privileges by copying a malicious drvstore.dll there.

    Published:28 Feb 2020
    9.8
    Critical

    CVE-2020-9380

    Last Modified: 21 Nov 2024

    IPTV Smarters WEB TV PLAYER through 2020-02-22 allows attackers to execute OS commands by uploading a script.

    Published:5 Mar 2020
    7.5
    High

    CVE-2020-9376

    Last Modified: 21 Nov 2024

    D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published:9 Jul 2020
    7.5
    High

    CVE-2020-9375

    Last Modified: 26 Mar 2020

    TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header containing an unexpected Referer field.

    Source:thewhiteh4t
    Published:25 Mar 2020
    9.8
    Critical

    CVE-2020-9374

    Last Modified: 2 Mar 2020

    On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends specific shell metacharacters to the panel's traceroute feature.

    Source:Elber Tavares
    Published:24 Feb 2020