Skip to main content

Year archive

CVEs published in 2020

Archive summary

18,322 CVEs published in 2020 — 2,625 Critical, 7,666 High, 7,546 Medium, 485 Low, 0 Unrated.

CVE-2020-24581

Published Dec 22, 2020

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_cmd.cgi feature (that is not reachable via the web user inte…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-24580

Published Dec 22, 2020

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. Lack of authentication functionality allows an attacker to assign a static IP addre…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24579

Published Dec 22, 2020

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authentication to access authenticated pag…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13547

Published Dec 22, 2020

A type confusion vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger an improper…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25106

Published Dec 22, 2020

Nanosystems SupRemo 4.1.3.2348 allows attackers to obtain LocalSystem access because File Manager can be used to rename Supremo.exe and then upload a Trojan horse with the Supremo…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13570

Published Dec 22, 2020

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger the reuse of prev…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13560

Published Dec 22, 2020

A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of pr…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13557

Published Dec 22, 2020

A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of pr…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-29396

Published Dec 22, 2020

A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote authenticated users to execute a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11786

Published Dec 22, 2020

Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to modify translated terms, which may lead to ar…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11785

Published Dec 22, 2020

Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to obtain access to m…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11784

Published Dec 22, 2020

Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to obtain access…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11783

Published Dec 22, 2020

Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11782

Published Dec 22, 2020

Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users with access to contact management to modify user…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11781

Published Dec 22, 2020

Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to trick victims into modifying thei…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-15645

Published Dec 22, 2020

Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users to create arbitrary records vi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15641

Published Dec 22, 2020

Cross-site scripting (XSS) issue in web module in Odoo Community 11.0 through 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote authenticated internal users to inject arbi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15638

Published Dec 22, 2020

Cross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote attackers to inject arbitrary web script in…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15634

Published Dec 22, 2020

Cross-site scripting (XSS) issue in attachment management in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote attackers to inject arbitrary web…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15633

Published Dec 22, 2020

Cross-site scripting (XSS) issue in "document" module in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to inject arbitrary web scri…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15632

Published Dec 22, 2020

Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty databa…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-28460

Published Dec 22, 2020

This affects the package multi-ini before 2.1.2. It is possible to pollute an object's prototype by specifying the constructor.proto object as part of an array. This is a bypass o…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28448

Published Dec 22, 2020

This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto object as part of an array.

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35626

Published Dec 21, 2020

An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 476-500 of 18,322 CVEsPage 20 of 733