Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Angry Yack Logo
Total 34640 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-29159 1 Zammad 1 Zammad 2024-11-21 4.0 MEDIUM 4.9 MEDIUM
An issue was discovered in Zammad before 3.5.1. The default signup Role (for newly created Users) can be a privileged Role, if configured by an admin. This behvaior was unintended.
CVE-2020-29069 1 Modern Honey Network Project 1 Modern Honey Network 2024-11-21 2.1 LOW 5.5 MEDIUM
_get_flag_ip_localdb in server/mhn/ui/utils.py in Modern Honey Network (MHN) through 2020-11-23 allows attackers to cause a denial-of-service via an IP address that is absent from a local geolocation database, because the code tries to uppercase a return value even if that value is not a string.
CVE-2020-29057 1 Cdatatec 56 72408a, 72408a Firmware, 9008a and 53 more 2024-11-21 7.8 HIGH 7.5 HIGH
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. It allows remote attackers to cause a denial of service (reboot) by sending random bytes to the telnet server on port 23, aka a "shawarma" attack.
CVE-2020-29041 1 Sesame-system 1 Web-sesame 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
A misconfiguration in Web-Sesame 2020.1.1.3375 allows an unauthenticated attacker to download the source code of the application, facilitating its comprehension (code review). Specifically, JavaScript source maps were inadvertently included in the production Webpack configuration. These maps contain sources used to generate the bundle, configuration settings (e.g., API keys), and developers' comments.
CVE-2020-29022 1 Secomea 8 Gatemanager 4250, Gatemanager 4250 Firmware, Gatemanager 4260 and 5 more 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager all versions prior to 9.3
CVE-2020-29000 1 Mygeeni 2 Gnc-cw013, Gnc-cw013 Firmware 2024-11-21 9.0 HIGH 7.2 HIGH
An issue was discovered on Geeni GNC-CW013 doorbell 1.8.1 devices. A vulnerability exists in the RTSP service that allows a remote attacker to take full control of the device with a high-privileged account. By sending a crafted message, an attacker is able to remotely deliver a telnet session. Any attacker that has the ability to control DNS can exploit this vulnerability to remotely login to the device and gain access to the camera system.
CVE-2020-28991 1 Gitea 1 Gitea 2024-11-21 7.5 HIGH 9.8 CRITICAL
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go.
CVE-2020-28984 2 Debian, Spip 2 Debian Linux, Spip 2024-11-21 7.5 HIGH 9.8 CRITICAL
prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.
CVE-2020-28975 1 Scikit-learn 1 Scikit-learn 2024-11-21 5.0 MEDIUM 7.5 HIGH
svm_predict_values in svm.cpp in Libsvm v324, as used in scikit-learn 0.23.2 and other products, allows attackers to cause a denial of service (segmentation fault) via a crafted model SVM (introduced via pickle, json, or any other model permanence standard) with a large value in the _n_support array. NOTE: the scikit-learn vendor's position is that the behavior can only occur if the library's API is violated by an application that changes a private attribute.
CVE-2020-28953 1 Bigbluebutton 1 Bigbluebutton 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
In BigBlueButton before 2.2.29, a user can vote more than once in a single poll.
CVE-2020-28925 1 Boltcms 1 Bolt 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How to Harden Your PHP for Better Security" guidance.
CVE-2020-28922 1 Pcanalyser 1 Pc Analyser 2024-11-21 7.2 HIGH 8.8 HIGH
An issue was discovered in Devid Espenschied PC Analyser through 4.10. The PCADRVX64.SYS kernel driver exposes IOCTL functionality that allows low-privilege users to read and write arbitrary physical memory. This could lead to arbitrary Ring-0 code execution and escalation of privileges.
CVE-2020-28921 1 Pcanalyser 1 Pc Analyser 2024-11-21 7.2 HIGH 8.8 HIGH
An issue was discovered in Devid Espenschied PC Analyser through 4.10. The PCADRVX64.SYS kernel driver exposes IOCTL functionality that allows low-privilege users to read and write to arbitrary Model Specific Registers (MSRs). This could lead to arbitrary Ring-0 code execution and escalation of privileges.
CVE-2020-28841 1 Drivergenius 1 Drivergenius Firmware 2024-11-21 7.1 HIGH 5.5 MEDIUM
MyDrivers64.sys in DriverGenius 9.61.3708.3054 allows attackers to cause a system crash via the ioctl command 0x9c402000 to \\.\MyDrivers0_0_1.
CVE-2020-28715 1 Leeco 2 Letv X43, Letv X43 Firmware 2024-11-21 N/A 9.8 CRITICAL
An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN02C080080B04121S, allows attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS).
CVE-2020-28672 1 Monocms 1 Monocms 2024-11-21 9.0 HIGH 7.2 HIGH
MonoCMS Blog 1.0 is affected by incorrect access control that can lead to remote arbitrary code execution. At monofiles/category.php:27, user input can be saved to category/[foldername]/index.php causing RCE.
CVE-2020-28653 1 Zohocorp 1 Manageengine Opmanager 2024-11-21 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.
CVE-2020-28583 1 Trendmicro 2 Apex One, Officescan 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version, build and patch information.
CVE-2020-28582 1 Trendmicro 2 Apex One, Officescan 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal number of managed agents.
CVE-2020-28577 1 Trendmicro 2 Apex One, Officescan 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal server hostname and db names.
CVE-2020-28576 1 Trendmicro 2 Apex One, Officescan 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version and build information.
CVE-2020-28573 1 Trendmicro 2 Apex One, Officescan 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal the total agents managed by the server.
CVE-2020-28572 2 Microsoft, Trendmicro 2 Windows, Apex One 2024-11-21 4.6 MEDIUM 7.8 HIGH
A vulnerability in Trend Micro Apex One could allow an unprivileged user to abuse the product installer to reinstall the agent with additional malicious code in the context of a higher privilege.
CVE-2020-28499 1 Merge Project 1 Merge 2024-11-21 7.5 HIGH 7.3 HIGH
All versions of package merge are vulnerable to Prototype Pollution via _recursiveMerge .
CVE-2020-28479 1 Jointjs 1 Jointjs 2024-11-21 5.0 MEDIUM 5.9 MEDIUM
The package jointjs before 3.3.0 are vulnerable to Denial of Service (DoS) via the unsetByPath function.
CVE-2020-28478 1 Greensock 1 Greensock Animation Platform 2024-11-21 5.0 MEDIUM 7.5 HIGH
This affects the package gsap before 3.6.0.
CVE-2020-28477 1 Immer Project 1 Immer 2024-11-21 5.0 MEDIUM 7.5 HIGH
This affects all versions of package immer.
CVE-2020-28472 1 Amazon 2 Aws Sdk For Javascipt, Aws Shared Configuration File Loader 2024-11-21 7.5 HIGH 7.3 HIGH
This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the context.
CVE-2020-28466 1 Nats 1 Nats Server 2024-11-21 5.0 MEDIUM 7.5 HIGH
This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that represent a service export/import cycles. Disclaimer from the maintainers: Running a NATS service which is exposed to untrusted users presents a heightened risk. Any remote execution flaw or equivalent seriousness, or denial-of-service by unauthenticated users, will lead to prompt releases by the NATS maintainers. Fixes for denial of service issues with n ...

Show More

CVE-2020-28421 2 Broadcom, Microsoft 2 Unified Infrastructure Management, Windows 2024-11-21 4.6 MEDIUM 7.8 HIGH
CA Unified Infrastructure Management 20.1 and earlier contains a vulnerability in the robot (controller) component that allows local attackers to elevate privileges.
CVE-2020-28419 1 Hp 1503 Laserjet Managed Mfp E62665 3gy14a, Laserjet Managed Mfp E62665 3gy15a, Laserjet Managed Mfp E62665 3gy16a and 1500 more 2024-11-21 6.8 MEDIUM 8.8 HIGH
During installation with certain driver software or application packages an arbitrary code execution could occur.
CVE-2020-28416 1 Hp 310 Officejet 250 Cz992a, Officejet 250 Cz992a Firmware, Officejet 250c L9d57a and 307 more 2024-11-21 4.6 MEDIUM 7.8 HIGH
HP has identified a security vulnerability with the I.R.I.S. OCR (Optical Character Recognition) software available with HP PageWide and OfficeJet printer software installations that could potentially allow unauthorized local code execution.
CVE-2020-28340 1 Google 1 Android 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypass Factory Reset Protection (FRP) via Secure Folder. The Samsung ID is SVE-2020-18546 (November 2020).
CVE-2020-28281 1 Set-object-value Project 1 Set-object-value 2024-11-21 7.5 HIGH 9.8 CRITICAL
Prototype pollution vulnerability in 'set-object-value' versions 0.0.0 through 0.0.5 allows an attacker to cause a denial of service and may lead to remote code execution.
CVE-2020-28280 1 Predefine Project 1 Predefine 2024-11-21 7.5 HIGH 9.8 CRITICAL
Prototype pollution vulnerability in 'predefine' versions 0.0.0 through 0.1.2 allows an attacker to cause a denial of service and may lead to remote code execution.
CVE-2020-28279 1 Flattenizer Project 1 Flattenizer 2024-11-21 7.5 HIGH 9.8 CRITICAL
Prototype pollution vulnerability in 'flattenizer' versions 0.0.5 through 1.0.5 allows an attacker to cause a denial of service and may lead to remote code execution.
CVE-2020-28278 1 Shvl Project 1 Shvl 2024-11-21 7.5 HIGH 9.8 CRITICAL
Prototype pollution vulnerability in 'shvl' versions 1.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
CVE-2020-28277 1 Dset Project 1 Dset 2024-11-21 7.5 HIGH 9.8 CRITICAL
Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
CVE-2020-28276 1 Deep-set Project 1 Deep-set 2024-11-21 7.5 HIGH 9.8 CRITICAL
Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
CVE-2020-28274 1 Deepref Project 1 Deepref 2024-11-21 7.5 HIGH 9.8 CRITICAL
Prototype pollution vulnerability in 'deepref' versions 1.1.1 through 1.2.1 allows attacker to cause a denial of service and may lead to remote code execution.