9.8
    Critical

    CVE-2020-8515

    Last Modified: 30 Mar 2020

    DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. This issue has been fixed in Vigor3900/2960/300B v1.5.1.

    Source:0xsha
    Published:1 Feb 2020
    6.1
    Medium

    CVE-2020-8512

    Last Modified: 3 Feb 2020

    In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.

    Source:Lutfu Mert Ceylan
    Published:31 Jan 2020
    6.5
    Medium

    CVE-2020-8505

    Last Modified: 10 Feb 2020

    School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user.

    Source:J3rryBl4nks
    Published:31 Jan 2020
    6.5
    Medium

    CVE-2020-8504

    Last Modified: 10 Feb 2020

    School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrative user.

    Source:J3rryBl4nks
    Published:31 Jan 2020
    7.5
    High

    CVE-2020-8495

    Last Modified: 5 Feb 2020

    In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate servlet allows an attacker with Timekeeper or Supervisor privileges to gain unauthorized administrative privileges within the application via the delegate, delegateRole, and delegatorUserId parameters.

    Source:nxkennedy
    Published:30 Jan 2020
    4.8
    Medium

    CVE-2020-8493

    Last Modified: 5 Feb 2020

    A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via multiple input fields (Login Message, Banner Message, and Password Instructions) of the com.threeis.webta.H261configMenu servlet via an authenticated administrator.

    Source:nxkennedy
    Published:30 Jan 2020
    7.5
    High

    CVE-2020-8437

    Last Modified: 21 Nov 2024

    The bencoding parser in BitTorrent uTorrent through 3.5.5 (build 45505) misparses nested bencoded dictionaries, which allows a remote attacker to cause a denial of service.

    Published:2 Mar 2020
    6.5
    Medium

    CVE-2020-8425

    Last Modified: 29 Jan 2020

    Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.

    Source:J3rryBl4nks
    Published:28 Jan 2020
    8.8
    High

    CVE-2020-8424

    Last Modified: 29 Jan 2020

    Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php.

    Source:J3rryBl4nks
    Published:28 Jan 2020
    7.2
    High

    CVE-2020-8423

    Last Modified: 21 Nov 2024

    A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the configuration of the Wi-Fi network.

    Published:2 Apr 2020
    8.8
    High

    CVE-2020-8417

    Last Modified: 21 Nov 2024

    The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.

    Published:28 Jan 2020
    7.5
    High

    CVE-2020-8416

    Last Modified: 3 Feb 2020

    IKTeam BearFTP before 0.2.0 allows remote attackers to achieve denial of service via a large volume of connections to the PASV mode port.

    Source:kolya5544
    Published:29 Jan 2020
    6.4
    Medium

    CVE-2020-8321

    Last Modified: 21 Nov 2024

    A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.

    Published:9 Jun 2020
    6.5
    Medium

    CVE-2020-8300

    Last Modified: 21 Nov 2024

    Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a SAML SP or a SAML IdP for this to be possible.

    Published:16 Jun 2021
    7.8
    High

    CVE-2020-8290

    Last Modified: 21 Nov 2024

    Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary.

    Published:27 Dec 2020
    7.8
    High

    CVE-2020-8289

    Last Modified: 21 Nov 2024

    Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of strings in URLs where validation is disabled leading to possible remote code execution via client update functionality.

    Published:27 Dec 2020
    6.5
    Medium

    CVE-2020-8287

    Last Modified: 30 Apr 2025

    Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggling.

    Published:4 Jan 2021
    7.5
    High

    CVE-2020-8277

    Last Modified: 30 Apr 2025

    A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.

    Published:12 Nov 2020
    8.8
    High

    CVE-2020-8254

    Last Modified: 21 Nov 2024

    A vulnerability in the Pulse Secure Desktop Client < 9.1R9 has Remote Code Execution (RCE) if users can be convinced to connect to a malicious server. This vulnerability only affects Windows PDC.To improve the security of connections between Pulse clients and Pulse Connect Secure, see below recommendation(s):Disable Dynamic certificate trust for PDC.

    Published:28 Oct 2020
    7.8
    High

    CVE-2020-8250

    Last Modified: 21 Nov 2024

    A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.

    Published:28 Oct 2020
    7.8
    High

    CVE-2020-8249

    Last Modified: 21 Nov 2024

    A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to perform buffer overflow.

    Published:28 Oct 2020
    7.8
    High

    CVE-2020-8248

    Last Modified: 21 Nov 2024

    A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.

    Published:28 Oct 2020
    7.5
    High

    CVE-2020-8241

    Last Modified: 21 Nov 2024

    A vulnerability in the Pulse Secure Desktop Client < 9.1R9 could allow the attacker to perform a MITM Attack if end users are convinced to connect to a malicious server.

    Published:28 Oct 2020
    7.2
    High

    CVE-2020-8218

    Last Modified: 30 Oct 2025

    A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

    Published:30 Jul 2020
    7.5
    High

    CVE-2020-8209

    Last Modified: 21 Nov 2024

    Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.

    Published:17 Aug 2020
    6.5
    Medium

    CVE-2020-8193

    Last Modified: 30 Oct 2025

    Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.

    Published:10 Jul 2020
    5.5
    Medium

    CVE-2020-8175

    Last Modified: 21 Nov 2024

    Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using specially a crafted JPEG image.

    Published:24 Jul 2020
    9.8
    Critical

    CVE-2020-8165

    Last Modified: 9 May 2025

    A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.

    Published:18 May 2020
    8.8
    High

    CVE-2020-8163

    Last Modified: 26 Jul 2020

    The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.

    Source:Lucas Amorim
    Published:15 May 2020
    7.5
    High

    CVE-2020-8162

    Last Modified: 21 Nov 2024

    A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.

    Published:18 May 2020
    9.8
    Critical

    CVE-2020-8158

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.

    Published:18 Sept 2020
    7.2
    High

    CVE-2020-8103

    Last Modified: 21 Nov 2024

    A vulnerability in the improper handling of symbolic links in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined file, and restore it to a privileged location. This issue affects Bitdefender Antivirus Free versions prior to 1.0.17.178.

    Published:5 Jun 2020
    7.5
    High

    CVE-2020-8036

    Last Modified: 21 Nov 2024

    The tok2strbuf() function in tcpdump 4.10.0-PRE-GIT was used by the SOME/IP dissector in an unsafe way.

    Published:29 Feb 2020
    9.8
    Critical

    CVE-2020-8012

    Last Modified: 2 Mar 2020

    CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component. A remote attacker can execute arbitrary code.

    Source:wetw0rk
    Published:18 Feb 2020
    7.5
    High

    CVE-2020-8004

    Last Modified: 21 Nov 2024

    STMicroelectronics STM32F1 devices have Incorrect Access Control.

    Published:6 Apr 2020
    8.8
    High

    CVE-2020-7991

    Last Modified: 3 Feb 2020

    Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.

    Source:Sarthak Saini
    Published:26 Jan 2020
    9.8
    Critical

    CVE-2020-7980

    Last Modified: 29 Jan 2020

    Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. NOTE: a valid sid cookie for a login to the intellian default account might be needed.

    Source:Xh4H
    Published:25 Jan 2020
    9.8
    Critical

    CVE-2020-7961

    Last Modified: 16 Apr 2020

    Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).

    Source:Metasploit
    Published:20 Mar 2020
    7.8
    High

    CVE-2020-7949

    Last Modified: 10 Feb 2020

    schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a GetValue call.

    Source:Bogdan Kurinnoy
    Published:27 Jan 2020
    5.4
    Medium

    CVE-2020-7934

    Last Modified: 23 Nov 2020

    In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue. Any user can modify these fields with a particular XSS payload, and it will be stored in the database. The payload will then be rendered when a user utilizes the search feature to search for other users (i.e., if a user with modified fields occurs in the search results). This issue was fixed in Liferay Portal CE version 7.3.0 GA1.

    Source:3ndG4me
    Published:28 Jan 2020
    8.8
    High

    CVE-2020-7931

    Last Modified: 21 Nov 2024

    In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modifying a .ssh/authorized_keys file. Patches are available for various versions between 5.11.8 and 6.16.0. The issue exists because use of the DefaultObjectWrapper class makes certain Java functions accessible to a template.

    Published:23 Jan 2020
    Unknown

    CVE-2020-7897

    https://github.com/mooneee/cve-2020-7897

    7.5
    High

    CVE-2020-7882

    Last Modified: 21 Nov 2024

    Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')

    Published:22 Nov 2021
    6.4
    Medium

    CVE-2020-7842

    Last Modified: 21 Nov 2024

    Improper Input validation vulnerability exists in Netis Korea D'live AP which could cause arbitrary command injection and execution when the time setting (using ntpServerlp1 parameter) for the users. This affects D'live set-top box AP(WF2429TB) v1.1.10.

    Published:20 Nov 2020
    7.2
    High

    CVE-2020-7799

    Last Modified: 21 Nov 2024

    An issue was discovered in FusionAuth before 1.11.0. An authenticated user, allowed to edit e-mail templates (Home -> Settings -> Email Templates) or themes (Home -> Settings -> Themes), can execute commands on the underlying operating system by abusing freemarker.template.utility.Execute in the Apache FreeMarker engine that processes custom templates.

    Published:28 Jan 2020
    9.6
    Critical

    CVE-2020-7750

    Last Modified: 29 Oct 2021

    This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMeasurements function.

    Source:Stig Magnus Baugstø
    Published:21 Oct 2020
    8.2
    High

    CVE-2020-7740

    Last Modified: 21 Nov 2024

    This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to the content given to node-pdf-generator, it is possible for an attacker to craft a url that will be passed to an external server allowing an SSRF attack.

    Published:6 Oct 2020
    7.5
    High

    CVE-2020-7699

    Last Modified: 21 Nov 2024

    This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.

    Published:30 Jul 2020
    5.3
    Medium

    CVE-2020-7693

    Last Modified: 21 Nov 2024

    Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.

    Published:3 Jul 2020
    7.4
    High

    CVE-2020-7692

    Last Modified: 21 Nov 2024

    PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorization request is the one that will be authorized. An attacker is able to obtain the authorization code using a malicious app on the client-side and use it to gain authorization to the protected resource. This affects the package com.google.oauth-client:google-oauth-client before 1.31.0.

    Published:3 Jul 2020