The product does not properly verify that the source of data or communication is valid.
557 vulnerabilities with CWE-346
CVE-2020-15733
MEDIUM
Bitdefender Antivirus Plus < 25.0.7.29 - Origin Validation Error in SafePay
CVSS 6.5
CVE-2020-26234
MEDIUM
Opencast < 7.9 - Man-in-the-Middle Attack via Disabled HTTPS Hostname Verification
CVSS 4.8
CVE-2020-26253
MEDIUM
Kirby CMS <3.3.6 & Kirby Panel <2.5.14 - Info Disclosure
CVSS 6.8
CVE-2020-3864
HIGH
iCloud for Windows <7.17 - Info Disclosure
CVSS 7.8
CVE-2020-15682
MEDIUM
Firefox < 82.0 - Origin Spoofing via External Protocol Prompt
CVSS 6.5
CVE-2020-16952
HIGH
Microsoft SharePoint Server-Side Include and ViewState RCE
CVSS 8.6
CVE-2020-16951
HIGH
Microsoft SharePoint - Remote Code Execution via Application Package Source Markup
CVSS 8.6
CVE-2020-9903
HIGH
Safari < 13.1.2 - Password Suggestion for Wrong Domain
CVSS 7.5
CVE-2020-26527
CRITICAL
Damstra Smart Asset 2020.7 - Origin Validation Error via API Version Endpoint
CVSS 9.8
CVE-2020-15773
MEDIUM
Gradle Enterprise < 2020.2.4 - Unauthenticated Data Exposure via Export API
CVSS 6.5
CVE-2020-14519
HIGH
CodeMeter < 7.00 - Origin Validation Error via WebSockets API
CVSS 7.5
CVE-2020-15652
MEDIUM
Firefox < 79.0 and Firefox ESR < 68.11 - Origin Validation Error via JavaScript Worker Stack Trace
CVSS 6.5
CVE-2020-16168
MEDIUM
temi_firmware < 1.3.7931 - Origin Validation Error
CVSS 6.5
CVE-2020-1449
HIGH
Microsoft Project - Remote Code Execution via Unchecked File Source Markup
CVSS 7.8
CVE-2020-1408
HIGH
Microsoft Windows Font Library - Remote Code Execution
CVSS 8.8
CVE-2020-15104
MEDIUM
Envoy <1.12.6-1.15.0 - Info Disclosure
CVSS 4.6
CVE-2020-14456
HIGH
Mattermost Desktop App < 4.4.0 - Origin Validation Error
CVSS 7.3
CVE-2020-12397
MEDIUM
Thunderbird <68.8.0 - Info Disclosure
CVSS 4.3
CVE-2020-11069
HIGH
TYPO3 CMS 9.0.0-9.5.16 and 10.0.0-10.4.1 - Same-Site Request Forgery via Malicious Uploaded Resource
CVSS 8.0
CVE-2020-11868
HIGH
ntp < 4.2.8p14 and 4.3.x < 4.3.100 - Unauthenticated Denial of Service via Spoofed Server Mode Packet
CVSS 7.5
CVE-2020-8984
HIGH
ZendTo < 5.22-2 Beta - IP Address Spoofing via X-Forwarded-For Header
CVSS 7.5
CVE-2020-8819
HIGH
CardGate Payments <3.1.15 - Auth Bypass
CVSS 8.1
CVE-2020-8818
HIGH
CardGate Payments <2.0.30 - Auth Bypass
CVSS 8.1
CVE-2020-0695
MEDIUM
Office Online Server - Spoofing via Origin Validation Error
CVSS 5.4
CVE-2020-0647
MEDIUM
Office Online Server - Spoofing via Origin Validation Error
CVSS 5.4
Details
Vulnerabilities
557