Unknown · CVSS Not scored
info.php in Logaritmo Aware CallManager 2012 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.
Published Sep 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password-reset link.
Published Sep 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
Published Sep 29, 2020 · Updated Aug 4, 2024
High · CVSS 7.5
jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m["aud"] (which is allowed by the specification). Because the type assertion fails, "" is the value of aud. This is a security problem if the JWT token is presented to a service that lacks its own audience check.
Published Sep 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497).
Published Sep 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even when the target page is protected against "page creation" and the attacker should not be able to create it. This occurs because of a mishandled distinction between an upload restriction and a create restriction. An attacker cannot leverage this to overwrite anything, but can leverage this to force a wiki to have a page with a disallowed title.
Published Sep 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Hoosk CMS v1.8.0. There is a SQL injection vulnerability in install/index.php
Published Sep 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).
Published Sep 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
XSS exists in the MobileFrontend extension for MediaWiki before 1.34.4 because section.line is mishandled during regex section line replacement from PageGateway. Using crafted HTML, an attacker can elicit an XSS attack via jQuery's parseHTML method, which can cause image callbacks to fire even without the element being appended to the DOM.
Published Sep 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569).
Published Sep 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564).
Published Sep 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The email quota cache in cPanel before 90.0.10 allows overwriting of files.
Published Sep 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
cPanel before 90.0.10 allows self XSS via the Cron Jobs interface (SEC-573).
Published Sep 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
cPanel before 90.0.10 allows self XSS via the Cron Editor interface (SEC-574).
Published Sep 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558).
Published Sep 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).
Published Sep 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566).
Published Sep 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491).
Published Sep 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
cPanel before 88.0.13 allows bypass of a protection mechanism that attempted to restrict package modification (SEC-557).
Published Sep 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Hoosk CMS v1.8.0. There is a XSS vulnerability in install/index.php
Published Sep 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets, bypassing security mechanisms, aka CID-26896f01467a.
Published Sep 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).
Published Sep 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).
Published Sep 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).
Published Sep 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).
Published Sep 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550).
Published Sep 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Hoosk CmS v1.8.0. There is an Remote Code Execution vulnerability in install/index.php
Published Sep 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).
Published Sep 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. Handling of actor ID does not necessarily use the correct database or correct wiki.
Published Sep 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding (except in Internet Explorer) and because a web page cannot specify that a client should make an additional HTTP request with an arbitrary Referer header
Published Sep 19, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in MantisBT before 2.24.3. Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when attempting to update said custom field via bug_actiongroup_page.php.
Published Sep 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of bounds checking. A crafted HTTP header can exploit this bug. NOTE: a committer has stated "this will not happen in practice.
Published Sep 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, XSS related to jQuery can occur. The attacker creates a message with [javascript:payload xss] and turns it into a jQuery object with mw.message().parse(). The expected result is that the jQuery object does not contain an <a> tag (or it does not have a href attribute, or it's empty, etc.). The actual result is that the object contains an <a href ="javascript... that executes when clicked.
Published Sep 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson.
Published Sep 23, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the InlineArray implementation, an unaligned reference may be generated for a type that has a large alignment requirement.
Published Sep 19, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their TTL because expiration time was not scheduled correctly. Fixed in 1.4.7 and 1.5.4.
Published Sep 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute low-privileged code on the target in order to exploit these vulnerabilities. The subs affected in this vulnerability makes it unique compared to similar CVEs such as CVE-2020-24564 and CVE-2020-25771.
Published Sep 28, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site level. Thus, multiple requests can be made across many wikis/sites concurrently.
Published Sep 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to trigger an out-of-bounds red information disclosure which would disclose sensitive information to an unprivileged account. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Published Sep 28, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading PHP files.
Published Sep 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, the array size is not checked when constructed with From<InlineArray<A, T>>.
Published Sep 19, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to execute arbitrary code on affected products. User interaction is required to exploit this vulnerability in that the target must import a corrupted configuration file.
Published Sep 28, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this report because "admins are considered trustworthy"; however, the behavior "contradicts our security policy" and is being fixed for 5.2
Published Sep 19, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
peg-markdown 0.4.14 has a NULL pointer dereference in process_raw_blocks in markdown_lib.c. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Published Sep 23, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default and static password. The Telnet service cannot be disabled and this password cannot be changed via standard functionality.
Published Sep 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could cause a denial of service (DoS) condition, because a symlink from %LOCALAPPDATA%\SaferVPN\Log is followed.
Published Sep 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in MediaWiki 1.34.x before 1.34.4. On Special:Contributions, the NS filter uses unescaped messages as keys in the option key for an HTMLForm specifier. This is vulnerable to a mild XSS if one of those messages is changed to include raw HTML.
Published Sep 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
webTareas through 2.1 allows files/Default/ Directory Listing.
Published Sep 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php.
Published Sep 17, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEventList::getFiltersDesc is insecurely using message text to build options names for an HTML multi-select field. The relevant code should use escaped() instead of text().
Published Sep 27, 2020 · Updated Aug 4, 2024