Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.8

    HIGH
    CVE-2020-9449

    An insecure random number generation vulnerability in BlaB! AX, BlaB! AX Pro, BlaB! WS (client), and BlaB! WS Pro (client) version 19.11 allows an attacker (with a guest or user session cookie) to escalate privileges by retrieving the cookie salt value an... Read more

    • Published: Feb. 28, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2020-9447

    There is an XSS (cross-site scripting) vulnerability in GwtUpload 1.0.3 in the file upload functionality. Someone can upload a file with a malicious filename, which contains JavaScript code, which would result in XSS. Cross-site scripting enables attacker... Read more

    Affected Products : gwtupload
    • Published: Feb. 28, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2020-9445

    Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.... Read more

    Affected Products : zulip_server
    • Published: Apr. 20, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2020-9444

    Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality.... Read more

    Affected Products : zulip_server
    • Published: Apr. 20, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2020-9443

    Zulip Desktop before 4.0.3 loaded untrusted content in an Electron webview with web security disabled, which can be exploited for XSS in a number of ways. This especially affects Zulip Desktop 2.3.82.... Read more

    Affected Products : zulip_desktop zulip_desktop
    • Published: Mar. 18, 2020
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2020-9442

    OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to gain privileges by copying a malicious drvstore.dll there.... Read more

    Affected Products : windows connect
    • Published: Feb. 28, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2020-9440

    A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML element into the editor.... Read more

    Affected Products : fedora ckeditor webspellchecker
    • Published: Mar. 10, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2020-9439

    Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Owl Tin Canny LearnDash Reporting before 3.4.4 allows authenticated remote attackers to inject arbitrary web script or HTML via the search_key GET Parameter in TinCan_Content_List_Table.php, m... Read more

    Affected Products : tin_canny_reporting_for_learndash
    • Published: Dec. 23, 2020
    • Modified: Nov. 21, 2024
  • 5.9

    MEDIUM
    CVE-2020-9438

    Tinxy Door Lock with firmware before 3.2 allow attackers to unlock a door by replaying an Unlock request that occurred when the attacker was previously authorized. In other words, door-access revocation is mishandled.... Read more

    • Published: Jun. 23, 2020
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2020-9437

    SecureAuth.aspx in SecureAuth IdP 9.3.0 suffers from a client-side template injection that allows for script execution, in the same manner as XSS.... Read more

    Affected Products : secureauth_identity_provider
    • Published: Jun. 25, 2020
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2020-9436

    PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devi... Read more

    • Published: Mar. 12, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2020-9435

    PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devi... Read more

    • Published: Mar. 12, 2020
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2020-9434

    openssl_x509_check_ip_asc in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.... Read more

    Affected Products : lua-openssl
    • Published: Feb. 27, 2020
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2020-9433

    openssl_x509_check_email in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.... Read more

    Affected Products : lua-openssl
    • Published: Feb. 27, 2020
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2020-9432

    openssl_x509_check_host in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.... Read more

    Affected Products : lua-openssl
    • Published: Feb. 27, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2020-9431

    In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory. This was addressed in epan/dissectors/packet-lte-rrc.c by adjusting certain append operations.... Read more

    Affected Products : fedora debian_linux leap wireshark
    • Published: Feb. 27, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2020-9430

    In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash. This was addressed in plugins/epan/wimax/msg_dlmap.c by validating a length field.... Read more

    Affected Products : fedora debian_linux leap wireshark
    • Published: Feb. 27, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2020-9429

    In Wireshark 3.2.0 to 3.2.1, the WireGuard dissector could crash. This was addressed in epan/dissectors/packet-wireguard.c by handling the situation where a certain data structure intentionally has a NULL value.... Read more

    Affected Products : leap wireshark
    • Published: Feb. 27, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2020-9428

    In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. This was addressed in epan/dissectors/packet-eap.c by using more careful sscanf parsing.... Read more

    Affected Products : fedora debian_linux leap wireshark
    • Published: Feb. 27, 2020
    • Modified: Nov. 21, 2024
  • 5.0

    MEDIUM
    CVE-2020-9427

    OX Guard 2.10.3 and earlier allows SSRF.... Read more

    Affected Products : ox_guard
    • Published: Jun. 15, 2020
    • Modified: Nov. 21, 2024
Showing 20 of 294842 Results