Enterprise Vulnerabilities
From DHS/US-CERT’s National Vulnerability Database

CVE-2020-26891
PUBLISHED: 2020-10-19

AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET parameter. This allows a remote attacker to execute an XSS attack on the domain Synapse is hosted on, by supplying the victim user with a malicious URL to the /_matrix/client/r0/auth/m…

CVE-2020-24265
PUBLISHED: 2020-10-19

An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in MemcmpInterceptorCommon() that can make tcpprep crash and cause a denial of service.

CVE-2020-24266
PUBLISHED: 2020-10-19

An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in get_l2len() that can make tcpprep crash and cause a denial of service.

CVE-2020-13778
PUBLISHED: 2020-10-19

rConfig 3.9.4 and earlier allows authenticated code execution (of system commands) by sending a forged GET request to lib/ajaxHandlers/ajaxAddTemplate.php or lib/ajaxHandlers/ajaxEditTemplate.php.

CVE-2020-15909
PUBLISHED: 2020-10-19

SolarWinds N-central through 2020.1 allows session hijacking.