Sitelet https://web.archive.org/web/20201216021918/https://nvd.nist.gov/


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, misconfigurations, product names, and impact metrics.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2020-27039 - In postNotification of ServiceRecord.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation... read CVE-2020-27039
    Published: December 15, 2020; 12:15:13 PM -0500

    V3.1: 5.5 MEDIUM
    V2.0: 2.1 LOW

  • CVE-2020-8920 - An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowin... read CVE-2020-8920
    Published: December 10, 2020; 6:15:11 AM -0500

    V3.1: 3.5 LOW
    V2.0: 2.7 LOW

  • CVE-2020-8919 - An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the default set of priviledges to read all other user's p... read CVE-2020-8919
    Published: December 10, 2020; 6:15:11 AM -0500

    V3.1: 3.5 LOW
    V2.0: 2.7 LOW

  • CVE-2020-7793 - The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).
    Published: December 11, 2020; 9:15:11 AM -0500

    V3.1: 7.5 HIGH
    V2.0: 5.0 MEDIUM

  • CVE-2020-35236 - The GitLab Webhook Handler in amazee.io Lagoon before 1.12.3 has incorrect access control associated with project deletion.
    Published: December 14, 2020; 12:15:10 AM -0500

    V3.1: 5.3 MEDIUM
    V2.0: 5.0 MEDIUM

  • CVE-2020-13985 - An issue was discovered in Contiki through 3.0. A memory corruption vulnerability exists in the uIP TCP/IP stack component when handling RPL extension headers of IPv6 network packets in rpl_remove_header in net/rpl/rpl-ext-header.c.
    Published: December 11, 2020; 5:15:12 PM -0500

    V3.1: 7.5 HIGH
    V2.0: 5.0 MEDIUM

  • CVE-2008-1945 - QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different ... read CVE-2008-1945
    Published: August 08, 2008; 3:41:00 PM -0400

    V2.0: 2.1 LOW

  • CVE-2007-1320 - Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related ... read CVE-2007-1320
    Published: May 02, 2007; 1:19:00 PM -0400

    V2.0: 7.2 HIGH

  • CVE-2007-1321 - Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" ... read CVE-2007-1321
    Published: October 30, 2007; 6:46:00 PM -0400

    V2.0: 7.2 HIGH

  • CVE-2007-1322 - QEMU 0.8.2 allows local users to halt a virtual machine by executing the icebp instruction.
    Published: May 02, 2007; 1:19:00 PM -0400

    V2.0: 2.1 LOW

  • CVE-2007-1366 - QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," which triggers a divide-by-zero error.
    Published: May 02, 2007; 1:19:00 PM -0400

    V2.0: 2.1 LOW

  • CVE-2007-5729 - The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp library, aka NE2000 "mtu" ... read CVE-2007-5729
    Published: October 30, 2007; 6:46:00 PM -0400

    V2.0: 7.2 HIGH

  • CVE-2007-5730 - Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via crafted data in the "net socket listen" option, aka QEMU "net socket" heap overflow. NOTE: some sources have us... read CVE-2007-5730
    Published: October 30, 2007; 6:46:00 PM -0400

    V2.0: 7.2 HIGH

  • CVE-2020-29669 - In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password. This process has a vulnerability which can be used to take over the administrator account and results in shell access. As the admin us... read CVE-2020-29669
    Published: December 13, 2020; 9:15:11 PM -0500

    V3.1: 8.8 HIGH
    V2.0: 9.0 HIGH

  • CVE-2020-35234 - The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file (such as... read CVE-2020-35234
    Published: December 13, 2020; 10:15:13 PM -0500

    V3.1: 7.5 HIGH
    V2.0: 5.0 MEDIUM

  • CVE-2020-35235 - ** UNSUPPORTED WHEN ASSIGNED ** vendor/elfinder/php/connector.minimal.php in the secure-file-manager plugin through 2.5 for WordPress loads elFinder code without proper access control. Thus, any authenticated user can run the elFinder upload comma... read CVE-2020-35235
    Published: December 13, 2020; 10:15:13 PM -0500

    V3.1: 8.8 HIGH
    V2.0: 6.5 MEDIUM

  • CVE-2020-8424 - Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php.
    Published: January 28, 2020; 6:15:12 PM -0500

    V3.1: 8.8 HIGH
    V2.0: 6.8 MEDIUM

  • CVE-2020-12025 - Rockwell Automation Logix Designer Studio 5000 Versions 32.00, 32.01, and 32.02 vulnerable to an xml external entity (XXE) vulnerability, which may allow an attacker to view hostnames or other resources from the program.
    Published: July 14, 2020; 9:15:11 AM -0400

    V3.1: 3.3 LOW
    V2.0: 4.3 MEDIUM

  • CVE-2020-5639 - Directory traversal vulnerability in FileZen versions from V3.0.0 to V4.2.2 allows remote attackers to upload an arbitrary file in a specific directory via unspecified vectors. As a result, an arbitrary OS command may be executed.
    Published: December 13, 2020; 10:15:13 PM -0500

    V3.1: 9.8 CRITICAL
    V2.0: 10.0 HIGH

  • CVE-2020-5665 - Improper check or handling of exceptional conditions in MELSEC iQ-F series FX5U(C) CPU unit firmware version 1.060 and earlier allows an attacker to cause a denial-of-service (DoS) condition on program execution and communication by sending a spec... read CVE-2020-5665
    Published: December 13, 2020; 10:15:13 PM -0500

    V3.1: 7.4 HIGH
    V2.0: 3.3 LOW