CVE-2020-12400
When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible tim
CVSS
4.7
Medio
EPSS
0.3%
p19
KEV
—
Exploit Today
6
0-100
Publicado: 8 oct 2020 · Última mod.: 19 ago 2026 · CWE-203
0.3%EPSS · 30 días0.3%
2026-08-042026-08-31
When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=1623116
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2023/02/msg00021.html
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2020-36/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2020-39/
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=1623116
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2023/02/msg00021.html
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2020-36/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2020-39/
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-78617—24.7%
——7WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked after a defined number of failed attempts, but this setting is not enabled by default.4dCVE-2026-370645.3 MED5.7%
——2User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via sending a specially crafted POST request to the affected endpoint with a chosen 'user_name' parameter to test if the user exists.9hCVE-2026-117545.3 MED15.0%
——4Observable discrepancy vulnerability in Seres Software syWEB allows Account Footprinting.
This issue affects syWEB: through 27082026.
NOTE: The vendor was contacted and it was learned that the product is not supported.5dCVE-2026-552274.3 MED8.0%
——2Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally scoped manner rather than restricting the lookup to projects the user can access, so they return HTTP 403 (Forbidden) instead of 404 (Not Found) when a user requests an object they are not authorized to see. This difference lets unauthorized users infer whether a given object exists in a private Weblate project. The issue has been fixed in version 2026.7.6dCVE-2026-792875.3 MED19.7%
——6Observable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)5dCVE-2026-792425.3 MED19.7%
——6Observable discrepancy in HTML in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)5d