Unknown

    CVE-2020-9373

    https://github.com/Limingxi6/cve-2020-9373-netgear-r6400

    7.8
    High

    CVE-2020-9372

    Last Modified: 12 Mar 2020

    The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.

    Source:Daniel Monzón
    Published:4 Mar 2020
    4.8
    Medium

    CVE-2020-9371

    Last Modified: 12 Mar 2020

    Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input could allow attackers to inject arbitrary JavaScript or HTML.

    Source:Daniel Monzón
    Published:4 Mar 2020
    7.8
    High

    CVE-2020-9332

    Last Modified: 21 Nov 2024

    ftusbbus2.sys in FabulaTech USB for Remote Desktop through 2020-02-19 allows privilege escalation via crafted IoCtl code related to a USB HID device.

    Published:17 Jun 2020
    7.5
    High

    CVE-2020-9289

    Last Modified: 21 Nov 2024

    Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access to the CLI configuration or the CLI backup file to decrypt the sensitive data, via knowledge of the hard-coded key.

    Published:16 Jun 2020
    7.5
    High

    CVE-2020-9283

    Last Modified: 24 Feb 2020

    golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack any SSH client.

    Source:Mark Adams
    Published:20 Feb 2020
    8.8
    High

    CVE-2020-9273

    Last Modified: 21 Nov 2024

    In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.

    Published:20 Feb 2020
    9.8
    Critical

    CVE-2020-9054

    Last Modified: 10 Nov 2025

    Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL NAS devices achieve authentication by using the weblogin.cgi CGI executable. This program fails to properly sanitize the username parameter that is passed to it. If the username parameter contains certain characters, it can allow command injection with the privileges of the web server that runs on the ZyXEL device. Although the web server does not run as the root user, ZyXEL devices include a setuid utility that can be leveraged to run any command with root privileges. As such, it should be assumed that exploitation of this vulnerability can lead to remote code execution with root privileges. By sending a specially-crafted HTTP POST or GET request to a vulnerable ZyXEL device, a remote, unauthenticated attacker may be able to execute arbitrary code on the device. This may happen by directly connecting to a device if it is directly exposed to an attacker. However, there are ways to trigger such crafted requests even if an attacker does not have direct connectivity to a vulnerable devices. For example, simply visiting a website can result in the compromise of any ZyXEL device that is reachable from the client system. Affected products include: NAS326 before firmware V5.21(AAZF.7)C0 NAS520 before firmware V5.21(AASZ.3)C0 NAS540 before firmware V5.21(AATB.4)C0 NAS542 before firmware V5.21(ABAG.4)C0 ZyXEL has made firmware updates available for NAS326, NAS520, NAS540, and NAS542 devices. Affected models that are end-of-support: NSA210, NSA220, NSA220+, NSA221, NSA310, NSA310S, NSA320, NSA320S, NSA325 and NSA325v2

    Published:4 Mar 2020
    6.8
    Medium

    CVE-2020-9047

    Last Modified: 21 Nov 2024

    A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior. An attacker with administrative privileges could potentially download and run a malicious executable that could allow OS command injection on the system.

    Published:26 Jun 2020
    5.4
    Medium

    CVE-2020-9038

    Last Modified: 2 Mar 2020

    Joplin through 1.0.184 allows Arbitrary File Read via XSS.

    Source:Javier Olmedo
    Published:17 Feb 2020
    5.4
    Medium

    CVE-2020-9008

    Last Modified: 21 Nov 2024

    Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web script via the Tile widget in the People Tool profile editor.

    Published:25 Feb 2020
    9.8
    Critical

    CVE-2020-9006

    Last Modified: 21 Nov 2024

    The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. This allows creation of an arbitrary WordPress Administrator account, leading to possible Remote Code Execution because Administrators can run PHP code on Wordpress instances. (This issue has been fixed in the 3.x branch of popup-builder.)

    Published:17 Feb 2020
    7.2
    High

    CVE-2020-8958

    Last Modified: 21 Nov 2024

    Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the boaform/admin/formPing Dest IP Address field.

    Published:15 Jul 2020
    7.8
    High

    CVE-2020-8950

    Last Modified: 21 Nov 2024

    The AUEPLauncher service in Radeon AMD User Experience Program Launcher through 1.0.0.1 on Windows allows elevation of privilege by placing a crafted file in %PROGRAMDATA%\AMD\PPC\upload and then creating a symbolic link in %PROGRAMDATA%\AMD\PPC\temp that points to an arbitrary folder with an arbitrary file name.

    Published:12 Feb 2020
    7.2
    High

    CVE-2020-8947

    Last Modified: 13 Feb 2020

    functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the index.php?operation/netflow/nf_live_view ip_dst, dst_port, or src_port parameter, a different vulnerability than CVE-2019-20224.

    Source:Engin Demirbilek
    Published:12 Feb 2020
    Unknown

    CVE-2020-8888

    https://github.com/SnipJoe/CVE-2020-8888

    6.5
    Medium

    CVE-2020-8866

    Last Modified: 12 Mar 2020

    This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. The specific flaw exists within add.php. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the www-data user. Was ZDI-CAN-10125.

    Source:Andrea Cardaci
    Published:23 Mar 2020
    6.3
    Medium

    CVE-2020-8865

    Last Modified: 12 Mar 2020

    This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. The specific flaw exists within edit.php. When parsing the params[template] parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the www-data user. Was ZDI-CAN-10469.

    Source:Andrea Cardaci
    Published:23 Mar 2020
    9.8
    Critical

    CVE-2020-8840

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.

    Published:10 Feb 2020
    6.1
    Medium

    CVE-2020-8839

    Last Modified: 12 Feb 2020

    Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cgi TF_submask field.

    Source:Luca.Chiou
    Published:12 Feb 2020
    7.8
    High

    CVE-2020-8835

    Last Modified: 21 Nov 2024

    In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was backported to that branch. This vulnerability was fixed in 5.6.1, 5.5.14, and 5.4.29. (issue is aka ZDI-CAN-10780)

    Published:30 Mar 2020
    5.4
    Medium

    CVE-2020-8825

    Last Modified: 11 Feb 2020

    index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.

    Source:Sayak Naskar
    Published:10 Feb 2020
    8.1
    High

    CVE-2020-8819

    Last Modified: 25 Feb 2020

    An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in the IPN callback processing function in cardgate/cardgate.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.) and therefore bypass the payment process (e.g., spoof an order status by manually sending an IPN callback request with a valid signature but without real payment) and/or receive all of the subsequent payments.

    Source:GeekHack
    Published:25 Feb 2020
    7.2
    High

    CVE-2020-8816

    Last Modified: 4 Aug 2020

    Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

    Source:Luis Vacacas
    Published:29 May 2020
    8.8
    High

    CVE-2020-8813

    Last Modified: 27 Feb 2020

    graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.

    Source:Askar
    Published:22 Feb 2020
    8.1
    High

    CVE-2020-8809

    Last Modified: 21 Nov 2024

    Gurux GXDLMS Director prior to 8.5.1905.1301 downloads updates to add-ins and OBIS code over an unencrypted HTTP connection. A man-in-the-middle attacker can prompt the user to download updates by modifying the contents of gurux.fi/obis/files.xml and gurux.fi/updates/updates.xml. Then, the attacker can modify the contents of downloaded files. In the case of add-ins (if the user is using those), this will lead to code execution. In case of OBIS codes (which the user is always using as they are needed to communicate with the energy meters), this can lead to code execution when combined with CVE-2020-8810.

    Published:25 Feb 2020
    9.8
    Critical

    CVE-2020-8794

    Last Modified: 9 Mar 2020

    OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.

    Source:Metasploit
    Published:25 Feb 2020
    4.7
    Medium

    CVE-2020-8793

    Last Modified: 26 Feb 2020

    OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c.

    Source:Qualys Corporation
    Published:25 Feb 2020
    5.4
    Medium

    CVE-2020-8778

    Last Modified: 3 Mar 2020

    Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write access to a project.

    Source:Alexandre ZANNI
    Published:2 Mar 2020
    5.4
    Medium

    CVE-2020-8777

    Last Modified: 3 Mar 2020

    Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT element in an SVG document.

    Source:Alexandre ZANNI
    Published:2 Mar 2020
    5.4
    Medium

    CVE-2020-8776

    Last Modified: 3 Mar 2020

    Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a file.

    Source:Alexandre ZANNI
    Published:2 Mar 2020
    9.8
    Critical

    CVE-2020-8657

    Last Modified: 5 Mar 2020

    An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attacker to calculate/guess the admin access token.

    Source:Metasploit
    Published:6 Feb 2020
    9.8
    Critical

    CVE-2020-8656

    Last Modified: 5 Mar 2020

    An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.

    Source:Metasploit
    Published:6 Feb 2020
    7.8
    High

    CVE-2020-8655

    Last Modified: 5 Mar 2020

    An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability, allowing the apache user to run arbitrary commands as root via a crafted NSE script for nmap 7.

    Source:Metasploit
    Published:6 Feb 2020
    8.8
    High

    CVE-2020-8654

    Last Modified: 5 Mar 2020

    An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the /module/module_frame/index.php autodiscovery.php target field.

    Source:Metasploit
    Published:6 Feb 2020
    9.8
    Critical

    CVE-2020-8644

    Last Modified: 16 Apr 2020

    PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.

    Source:Metasploit
    Published:5 Feb 2020
    8.8
    High

    CVE-2020-8639

    Last Modified: 15 Feb 2021

    An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. This allows an authenticated attacker to upload a malicious file (containing PHP code to execute operating system commands) to a publicly accessible directory of the application.

    Source:snovvcrash
    Published:3 Apr 2020
    9.8
    Critical

    CVE-2020-8637

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter.

    Published:3 Apr 2020
    9.8
    Critical

    CVE-2020-8636

    Last Modified: 21 Nov 2024

    An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution .

    Published:6 Feb 2020
    7.8
    High

    CVE-2020-8635

    Last Modified: 21 Nov 2024

    Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local users to arbitrarily create FTP users with full privileges, and escalate privileges within the operating system by modifying system files.

    Published:6 Mar 2020
    7.5
    High

    CVE-2020-8617

    Last Modified: 27 May 2020

    Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local session key even on servers whose configuration does not otherwise make use of it, almost all current BIND servers are vulnerable. In releases of BIND dating from March 2018 and after, an assertion check in tsig.c detects this inconsistent state and deliberately exits. Prior to the introduction of the check the server would continue operating in an inconsistent state, with potentially harmful results.

    Source:Teppei Fukuda
    Published:19 May 2020
    6.5
    Medium

    CVE-2020-8615

    Last Modified: 2 Mar 2020

    A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).

    Source:Jinson Varghese Behanan
    Published:4 Feb 2020
    8.8
    High

    CVE-2020-8605

    Last Modified: 14 Jul 2020

    A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected installations. Authentication is required to exploit this vulnerability.

    Source:Mehmet Ince
    Published:27 May 2020
    9.8
    Critical

    CVE-2020-8597

    Last Modified: 3 Dec 2025

    eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.

    Published:3 Feb 2020
    9.1
    Critical

    CVE-2020-8570

    Last Modified: 21 Nov 2024

    Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.

    Published:12 Jan 2021
    6.4
    Medium

    CVE-2020-8559

    Last Modified: 21 Nov 2024

    The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.

    Published:15 Jul 2020
    5.4
    Medium

    CVE-2020-8558

    Last Modified: 21 Nov 2024

    The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's network namespace. Such a service is generally thought to be reachable only by other processes on the same host, but due to this defeect, could be reachable by other hosts on the same LAN as the node, or by containers running on the same node as the service.

    Published:8 Jul 2020
    6.3
    Medium

    CVE-2020-8554

    Last Modified: 1 Jun 2026

    Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.

    Published:7 Dec 2020
    9.8
    Critical

    CVE-2020-8547

    Last Modified: 4 Feb 2020

    phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.

    Source:Suvadip Kar
    Published:3 Feb 2020
    9.8
    Critical

    CVE-2020-8518

    Last Modified: 14 Mar 2020

    Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.

    Source:Andrea Cardaci
    Published:17 Feb 2020