Latest CVE Feed
-
8.8
HIGHCVE-2020-9449
An insecure random number generation vulnerability in BlaB! AX, BlaB! AX Pro, BlaB! WS (client), and BlaB! WS Pro (client) version 19.11 allows an attacker (with a guest or user session cookie) to escalate privileges by retrieving the cookie salt value an... Read more
- Published: Feb. 28, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2020-9447
There is an XSS (cross-site scripting) vulnerability in GwtUpload 1.0.3 in the file upload functionality. Someone can upload a file with a malicious filename, which contains JavaScript code, which would result in XSS. Cross-site scripting enables attacker... Read more
Affected Products : gwtupload- Published: Feb. 28, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2020-9445
Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.... Read more
Affected Products : zulip_server- Published: Apr. 20, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2020-9444
Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality.... Read more
Affected Products : zulip_server- Published: Apr. 20, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2020-9443
Zulip Desktop before 4.0.3 loaded untrusted content in an Electron webview with web security disabled, which can be exploited for XSS in a number of ways. This especially affects Zulip Desktop 2.3.82.... Read more
- Published: Mar. 18, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-9442
OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to gain privileges by copying a malicious drvstore.dll there.... Read more
- Published: Feb. 28, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2020-9440
A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML element into the editor.... Read more
- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2020-9439
Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Owl Tin Canny LearnDash Reporting before 3.4.4 allows authenticated remote attackers to inject arbitrary web script or HTML via the search_key GET Parameter in TinCan_Content_List_Table.php, m... Read more
Affected Products : tin_canny_reporting_for_learndash- Published: Dec. 23, 2020
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2020-9438
Tinxy Door Lock with firmware before 3.2 allow attackers to unlock a door by replaying an Unlock request that occurred when the attacker was previously authorized. In other words, door-access revocation is mishandled.... Read more
- Published: Jun. 23, 2020
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2020-9437
SecureAuth.aspx in SecureAuth IdP 9.3.0 suffers from a client-side template injection that allows for script execution, in the same manner as XSS.... Read more
Affected Products : secureauth_identity_provider- Published: Jun. 25, 2020
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2020-9436
PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devi... Read more
Affected Products : tc_cloud_client_1002-4g_firmware tc_router_3002t-4g_att_firmware tc_router_3002t-4g_firmware tc_router_3002t-4g_vzw_firmware tc_router_2002t-3g_firmware tc_cloud_client_1002-txtx_firmware tc_router_3002t-4g tc_router_2002t-3g tc_router_3002t-4g_vzw tc_router_3002t-4g_att +2 more products- Published: Mar. 12, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9435
PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devi... Read more
Affected Products : tc_cloud_client_1002-4g_firmware tc_router_3002t-4g_att_firmware tc_router_3002t-4g_firmware tc_router_3002t-4g_vzw_firmware tc_router_2002t-3g_firmware tc_cloud_client_1002-txtx_firmware tc_router_3002t-4g tc_router_2002t-3g tc_router_3002t-4g_vzw tc_router_3002t-4g_att +2 more products- Published: Mar. 12, 2020
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2020-9434
openssl_x509_check_ip_asc in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.... Read more
Affected Products : lua-openssl- Published: Feb. 27, 2020
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2020-9433
openssl_x509_check_email in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.... Read more
Affected Products : lua-openssl- Published: Feb. 27, 2020
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2020-9432
openssl_x509_check_host in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.... Read more
Affected Products : lua-openssl- Published: Feb. 27, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9431
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory. This was addressed in epan/dissectors/packet-lte-rrc.c by adjusting certain append operations.... Read more
- Published: Feb. 27, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9430
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash. This was addressed in plugins/epan/wimax/msg_dlmap.c by validating a length field.... Read more
- Published: Feb. 27, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9429
In Wireshark 3.2.0 to 3.2.1, the WireGuard dissector could crash. This was addressed in epan/dissectors/packet-wireguard.c by handling the situation where a certain data structure intentionally has a NULL value.... Read more
- Published: Feb. 27, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9428
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. This was addressed in epan/dissectors/packet-eap.c by using more careful sscanf parsing.... Read more
- Published: Feb. 27, 2020
- Modified: Nov. 21, 2024
-
5.0
MEDIUM- Published: Jun. 15, 2020
- Modified: Nov. 21, 2024