Unknown · CVSS Not scored
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/tree.php?subdomain=SSRF.
Published Nov 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/get.php?subdomain=SSRF.
Published Nov 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
Published Nov 19, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/detail.php?subdomain=SSRF.
Published Nov 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_strdup in util.c.
Published Nov 19, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow).
Published Nov 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is a Stored XSS in Magicpin v2.1 in the User Registration section. Each time an admin visits the manage user section from the admin panel, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.
Published Nov 23, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue exists in PrimeKey EJBCA before 7.4.3 when enrolling with EST while proxied through an RA over the Peers protocol. As a part of EJBCA's domain security model, the peer connector allows the restriction of client certificates (for the RA, not the end user) to a limited set of allowed CAs, thus restricting the accessibility of that RA to the rights it has within a specific role. While this works for other protocols such as CMP, it was found that the EJBCA enrollment over an EST implementation bypasses this check, allowing enrollment with a valid client certificate through any functioning and authenticated RA connected to the CA. NOTE: an attacker must already have a trusted client certificate and authorization to enroll against the targeted CA.
Published Nov 19, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Devid Espenschied PC Analyser through 4.10. The PCADRVX64.SYS kernel driver exposes IOCTL functionality that allows low-privilege users to read and write arbitrary physical memory. This could lead to arbitrary Ring-0 code execution and escalation of privileges.
Published Nov 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath volume and mounting either a file or directory into a container as readonly, the file/directory is mounted as readOnly inside the container, but is still writable inside the guest. For a container breakout situation, a malicious guest can potentially modify or delete files/directories expected to be read-only.
Published Nov 17, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak passwords with much less entropy than advertised. The suggested passwords depend deterministically on the time the second rclone was started. This limits the entropy of the passwords enormously. These passwords are often used in the crypt backend for encryption of data. It would be possible to make a dictionary of all possible passwords with about 38 million entries per password length. This would make decryption of secret material possible with a plausible amount of effort. NOTE: all passwords generated by affected versions should be changed.
Published Nov 19, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle.
Published Nov 23, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer overflow in in the copy_msg_element function for the devDiscoverHandle server in the TP-Link WR and WDR series, including WDR7400, WDR7500, WDR7660, WDR7800, WDR8400, WDR8500, WDR8600, WDR8620, WDR8640, WDR8660, WR880N, WR886N, WR890N, WR890N, WR882N, and WR708N.
Published Nov 20, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local attackers to read kernel memory, aka CID-6735b4632def.
Published Nov 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug resulting in a buffer overflow in calls to memcpy/memmove.
Published Nov 30, 2020 · Updated Aug 4, 2024
High · CVSS 8.8
The orbisius-child-theme-creator plugin before 1.5.2 for WordPress allows CSRF via orbisius_ctc_theme_editor_manage_file.
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.
Published Nov 18, 2020 · Updated Aug 4, 2024
Medium · CVSS 6.4
The WPBakery plugin before 6.4.1 for WordPress allows XSS because it calls kses_remove_filters to disable the standard WordPress XSS protection mechanism for the Author and Contributor roles.
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A SQL injection vulnerability in TopicMapper.xml of PybbsCMS v5.2.1 allows attackers to access sensitive database information.
Published Nov 1, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim's browser (XSS).
Published Nov 17, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious payload in admin's portal thus leads to compromise admin's system.
Published Nov 20, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Devid Espenschied PC Analyser through 4.10. The PCADRVX64.SYS kernel driver exposes IOCTL functionality that allows low-privilege users to read and write to arbitrary Model Specific Registers (MSRs). This could lead to arbitrary Ring-0 code execution and escalation of privileges.
Published Nov 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer overflow in WinSCP 5.17.8 allows a malicious FTP server to cause a denial of service or possibly have other unspecified impact via a long file name.
Published Nov 23, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the view_statistics (aka View frontend statistics) extension before 2.0.1 for TYPO3. It saves all GET and POST data of TYPO3 frontend requests to the database. Depending on the extensions used on a TYPO3 website, sensitive data (e.g., cleartext passwords if ext:felogin is installed) may be saved.
Published Nov 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.
Published Nov 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to execute remote code.
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Memory leak in IPv6Param::setAddress in CloudAvid PParam 1.3.1.
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
Published Nov 17, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The update functionality of the Discover Media infotainment system in Volkswagen Polo 2019 vehicles allows physically proximate attackers to execute arbitrary code because some unsigned parts of a metainfo file are parsed, which can cause attacker-controlled files to be written to the infotainment system and executed as root.
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it easier for remote attackers to conduct admin Account Takeover attacks.
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
Published Nov 17, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Gila CMS 1.16.0, an attacker can upload a shell to tmp directy and abuse .htaccess through the logs function for executing PHP files.
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php.
Published Nov 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing affected users' files to be encrypted with "tomb {W] Detected DISPLAY, but only pinentry-curses is found." as the encryption key.
Published Nov 13, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploading a theme, and executing the PHP file via an HTTP GET request to /themes/<php_file_name>
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A unauthenticated path traversal arbitrary remote file deletion vulnerability in Trend Micro Worry-Free Business Security 10 SP1 could allow an unauthenticated attacker to exploit the vulnerability and modify or delete arbitrary files on the product's management console.
Published Nov 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability in Trend Micro Apex One could allow an unprivileged user to abuse the product installer to reinstall the agent with additional malicious code in the context of a higher privilege.
Published Nov 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A command injection vulnerability in ModifyVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.
Published Nov 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an unauthenticated, remote attacker to send a specially crafted HTTP message and achieve remote code execution with elevated privileges.
Published Nov 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send a specially crafted HTTP message and achieve remote code execution with elevated privileges.
Published Nov 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The server in Dundas BI through 8.0.0.1001 allows XSS via an HTML label when creating or editing a dashboard.
Published Nov 10, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability affects the Web UI in Locust before 1.3.2, if the installation violates the usage expectations by exposing this UI to outside users.
Published Nov 9, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Cross Site Scripting (XSS) vulnerability exists in OPAC in Sokrates SOWA SowaSQL through 5.6.1 via the sowacgi.php typ parameter.
Published Nov 19, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
CA Unified Infrastructure Management 20.1 and earlier contains a vulnerability in the robot (controller) component that allows local attackers to elevate privileges.
Published Nov 23, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Kamailio before 5.4.0, as used in Sip Express Router (SER) in Sippy Softswitch 4.5 through 5.2 and other products, allows a bypass of a header-removal protection mechanism via whitespace characters. This occurs in the remove_hf function in the Kamailio textops module. Particular use of remove_hf in Sippy Softswitch may allow skilled attacker having a valid credential in the system to disrupt internal call start/duration accounting mechanisms leading potentially to a loss of revenue.
Published Nov 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
During installation with certain driver software or application packages an arbitrary code execution could occur.
Published Nov 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in ReadyTalk Avian 1.2.0 before 2020-10-27. The FileOutputStream.write() method in FileOutputStream.java has a boundary check to prevent out-of-bounds memory read/write operations. However, an integer overflow leads to bypassing this check and achieving the out-of-bounds access. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Published Nov 9, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
Published Nov 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The server in Dundas BI through 8.0.0.1001 allows XSS via addition of a Component (e.g., a button) when events such as click, hover, etc. occur.
Published Nov 10, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
HP has identified a security vulnerability with the I.R.I.S. OCR (Optical Character Recognition) software available with HP PageWide and OfficeJet printer software installations that could potentially allow unauthorized local code execution.
Published Nov 3, 2021 · Updated Aug 4, 2024