6.1
    Medium

    CVE-2020-7680

    Last Modified: 22 Jul 2020

    docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters after # sign) to load resources from server-side .md files. Due to lack of validation here, it is possible to provide external URLs after the /#/ (domain.com/#//attacker.com) and render arbitrary JavaScript/HTML inside docsify page.

    Source:Amin Sharifi
    Published:20 Jul 2020
    7.5
    High

    CVE-2020-7661

    Last Modified: 21 Nov 2024

    all versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long string in String.test can cause a Denial of Service.

    Published:4 Jun 2020
    6.1
    Medium

    CVE-2020-7656

    Last Modified: 8 Apr 2025

    jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.

    Source:xOryus
    Published:19 May 2020
    9.8
    Critical

    CVE-2020-7602

    Last Modified: 21 Nov 2024

    node-prompt-here through 1.0.1 allows execution of arbitrary commands. The "runCommand()" is called by "getDevices()" function in file "linux/manager.js", which is required by the "index. process.env.NM_CLI" in the file "linux/manager.js". This function is used to construct the argument of function "execSync()", which can be controlled by users without any sanitization.

    Published:15 Mar 2020
    5.6
    Medium

    CVE-2020-7598

    Last Modified: 21 Nov 2024

    minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.

    Published:10 Mar 2020
    7.5
    High

    CVE-2020-7473

    Last Modified: 21 Nov 2024

    In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, allow unauthenticated attackers to access the documents and folders of ShareFile users. NOTE: unlike most CVEs, exploitability depends on the product version that was in use when a particular setup step was performed, NOT the product version that is in use during a current assessment of a CVE consumer's product inventory. Specifically, the vulnerability can be exploited if a storage zone was created by one of these product versions: 5.9.0, 5.8.0, 5.7.0, 5.6.0, 5.5.0, or earlier. This CVE differs from CVE-2020-8982 and CVE-2020-8983 but has essentially the same risk.

    Published:7 May 2020
    9.8
    Critical

    CVE-2020-7471

    Last Modified: 21 Nov 2024

    Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data as a series of rows with a user-specified column delimiter). By passing a suitably crafted delimiter to a contrib.postgres.aggregates.StringAgg instance, it was possible to break escaping and inject malicious SQL.

    Published:3 Feb 2020
    7.3
    High

    CVE-2020-7461

    Last Modified: 21 Nov 2024

    In FreeBSD 12.1-STABLE before r365010, 11.4-STABLE before r365011, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, dhclient(8) fails to handle certain malformed input related to handling of DHCP option 119 resulting a heap overflow. The heap overflow could in principle be exploited to achieve remote code execution. The affected process runs with reduced privileges in a Capsicum sandbox, limiting the immediate impact of an exploit.

    Published:26 Mar 2021
    10
    Critical

    CVE-2020-7388

    Last Modified: 21 Nov 2024

    Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential validation. While exploiting this does require knowledge of the installation path, that information can be learned by exploiting CVE-2020-7387. This issue was fixed in AdxAdmin 93.2.53, which ships with updates for on-premises versions of Sage X3 including Version 9 (components shipped with Syracuse 9.22.7.2 and later), Sage X3 HR & Payroll Version 9 (those components that ship with Syracuse 9.24.1.3), Version 11 (components shipped with Syracuse 11.25.2.6 and later), and Version 12 (components shipped with Syracuse 12.10.2.8 and later) of Sage X3. Other on-premises versions of Sage X3 are unsupported by the vendor.

    Published:22 Jul 2021
    7
    High

    CVE-2020-7384

    Last Modified: 28 Jan 2021

    Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine.

    Source:Justin Steven
    Published:29 Oct 2020
    9.1
    Critical

    CVE-2020-7378

    Last Modified: 21 Nov 2024

    CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. An attacker who is able to connect to the affected OpenCRX instance can change the password of any user, including admin-Standard, to any chosen value. This issue was resolved in version 5.0-20200904, released September 4, 2020.

    Published:24 Nov 2020
    8.4
    High

    CVE-2020-7352

    Last Modified: 21 Nov 2024

    The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to the software shipping with embedded, static RSA private key, an attacker with this key material and local user permissions can effectively send any operating system command to the service for execution in this elevated context. The service listens for such commands on a locally-bound network port, localhost:9978. A Metasploit module has been published which exploits this vulnerability. This issue affects the 2.0.x branch of the software (2.0.12 and earlier) as well as the 1.2.x branch (1.2.64 and earlier). A fix was issued for the 2.0.x branch of the affected software.

    Published:6 Aug 2020
    7.5
    High

    CVE-2020-7283

    Last Modified: 21 Nov 2024

    Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edit files via symbolic link manipulation in a location they would otherwise not have access to. This is achieved through running a malicious script or program on the target machine.

    Published:3 Jul 2020
    9.8
    Critical

    CVE-2020-7247

    Last Modified: 10 Feb 2020

    smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This affects the "uncommented" default configuration. The issue exists because of an incorrect return value upon failure of input validation.

    Source:Metasploit
    Published:29 Jan 2020
    8.8
    High

    CVE-2020-7246

    Last Modified: 28 Feb 2020

    A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo functionality, by leveraging a path traversal vulnerability in the users['photop_preview'] delete photo feature, allowing bypass of .htaccess protection. NOTE: this issue exists because of an incomplete fix for CVE-2015-3884.

    Source:Tobin Shields
    Published:21 Jan 2020
    9.8
    Critical

    CVE-2020-7209

    Last Modified: 18 May 2020

    LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.

    Source:Cody Winkler
    Published:12 Feb 2020
    9.8
    Critical

    CVE-2020-7200

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerability could be exploited to allow remote code execution.

    Published:18 Dec 2020
    9.8
    Critical

    CVE-2020-7115

    Last Modified: 10 Jul 2020

    The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.

    Source:SpicyItalian
    Published:3 Jun 2020
    5.4
    Medium

    CVE-2020-7108

    Last Modified: 12 Feb 2020

    The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.

    Source:Jinson Varghese Behanan
    Published:16 Jan 2020
    9.1
    Critical

    CVE-2020-7048

    Last Modified: 21 Nov 2024

    The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state (deleting all site content stored in that table), as demonstrated by a wp-admin/admin-post.php?db-reset-tables[]=comments URI.

    Published:16 Jan 2020
    5.5
    Medium

    CVE-2020-7030

    Last Modified: 12 Jun 2020

    A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component. Affected versions of IP Office include: 9.x, 10.0 through 10.1.0.7 and 11.0 though 11.0.4.3.

    Source:hyp3rlinx
    Published:3 Jun 2020
    6.5
    Medium

    CVE-2020-6950

    Last Modified: 21 Nov 2024

    Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.

    Published:20 Feb 2020
    Low

    CVE-2020-6888

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none

    Published:5 Jan 2021
    6.5
    Medium

    CVE-2020-6864

    Last Modified: 21 Nov 2024

    ZTE E8820V3 router product is impacted by an information leak vulnerability. Attackers could use this vulnerability to to gain wireless passwords. After obtaining the wireless password, the attacker could collect information and attack the router.

    Published:27 Feb 2020
    5.3
    Medium

    CVE-2020-6862

    Last Modified: 10 Sept 2020

    V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to obtain page information without entering a verification code.

    Source:Hritik Vijay
    Published:17 Jan 2020
    5.5
    Medium

    CVE-2020-6861

    Last Modified: 21 Nov 2024

    A flawed protocol design in the Ledger Monero app before 1.5.1 for Ledger Nano and Ledger S devices allows a local attacker to extract the master spending key by sending crafted messages to this app selected on a PIN-entered Ledger connected to a host PC.

    Published:6 May 2020
    5.5
    Medium

    CVE-2020-6857

    Last Modified: 21 Apr 2020

    CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FTP server passwords is hard-coded in the binary.

    Source:hyp3rlinx
    Published:21 Jan 2020
    9.8
    Critical

    CVE-2020-6756

    Last Modified: 10 Jan 2020

    languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the lang parameter.

    Source:.:UND3R:.
    Published:9 Jan 2020
    8.3
    High

    CVE-2020-6650

    Last Modified: 21 Nov 2024

    UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval” in “Update Manager” class when software attempts to see if there are updates available. This results in arbitrary code execution on the machine where software is installed.

    Published:23 Mar 2020
    9.8
    Critical

    CVE-2020-6627

    Last Modified: 25 May 2023

    The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.

    Source:Ege Balci
    Published:6 Dec 2022
    6.5
    Medium

    CVE-2020-6519

    Last Modified: 4 Dec 2020

    Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.

    Source:Gal Weizman
    Published:14 Jul 2020
    4.3
    Medium

    CVE-2020-6516

    Last Modified: 21 Nov 2024

    Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published:14 Jul 2020
    6.5
    Medium

    CVE-2020-6514

    Last Modified: 21 Nov 2024

    Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.

    Published:14 Jul 2020
    8.8
    High

    CVE-2020-6507

    Last Modified: 7 Apr 2021

    Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Source:r4j0x00
    Published:15 Jun 2020
    8.8
    High

    CVE-2020-6468

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published:19 May 2020
    8.8
    High

    CVE-2020-6418

    Last Modified: 9 Mar 2020

    Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Source:Metasploit
    Published:24 Feb 2020
    10
    Critical

    CVE-2020-6364

    Last Modified: 21 Nov 2024

    SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that OS commands can be executed and potentially gain control over the host running the CA Introscope Enterprise Manager,leading to Code Injection. With this, the attacker is able to read and modify all system files and also impact system availability.

    Published:15 Oct 2020
    5.3
    Medium

    CVE-2020-6308

    Last Modified: 21 Nov 2024

    SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine internal infrastructure and gather information for further attacks like remote file inclusion, retrieve server files, bypass firewall and force the vulnerable server to perform malicious requests, resulting in a Server-Side Request Forgery vulnerability.

    Published:20 Oct 2020
    10
    Critical

    CVE-2020-6287

    Last Modified: 31 Oct 2025

    SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.

    Published:14 Jul 2020
    5.3
    Medium

    CVE-2020-6286

    Last Modified: 21 Nov 2024

    The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method to download zip files to a specific directory, leading to Path Traversal.

    Published:14 Jul 2020
    9.8
    Critical

    CVE-2020-6207

    Last Modified: 31 Oct 2025

    SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.

    Published:10 Mar 2020
    9.8
    Critical

    CVE-2020-6170

    Last Modified: 28 Jan 2020

    An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the HTML source code of the cgi-bin/index2.asp URI.

    Source:Husinul Sanub
    Published:8 Jan 2020
    8.8
    High

    CVE-2020-6010

    Last Modified: 19 Jul 2021

    LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection

    Source:nhattruong
    Published:30 Apr 2020
    6.1
    Medium

    CVE-2020-5903

    Last Modified: 21 Nov 2024

    In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.

    Published:1 Jul 2020
    9.8
    Critical

    CVE-2020-5902

    Last Modified: 26 Jul 2020

    In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.

    Source:Carlos E. Vieira
    Published:1 Jul 2020
    7.5
    High

    CVE-2020-5849

    Last Modified: 20 Apr 2020

    Unraid 6.8.0 allows authentication bypass.

    Source:Metasploit
    Published:16 Mar 2020
    9.8
    Critical

    CVE-2020-5847

    Last Modified: 20 Apr 2020

    Unraid through 6.8.0 allows Remote Code Execution.

    Source:Metasploit
    Published:16 Mar 2020
    7.2
    High

    CVE-2020-5844

    Last Modified: 14 Jun 2022

    index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020.

    Source:UNICORD
    Published:16 Mar 2020
    6.1
    Medium

    CVE-2020-5842

    Last Modified: 21 Nov 2024

    Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI. The payload is, for example, executed on the admin/index.php?page=users/manage page.

    Published:7 Jan 2020
    7.5
    High

    CVE-2020-5839

    Last Modified: 21 Nov 2024

    Symantec Endpoint Detection And Response, prior to 4.4, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.

    Published:8 Jul 2020