CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2020-4174

    Last Modified: 21 Nov 2024

    IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174683.

    Published: 27 Aug 2020
    7.5
    High

    CVE-2012-2201

    Last Modified: 21 Nov 2024

    IBM WebSphere MQ 7.1 is vulnerable to a denial of service, caused by an error when handling user ids. A remote attacker could exploit this vulnerability to bypass the security configuration setup on a SVRCONN channel and flood the queue manager.

    Published: 27 Aug 2020
    6.1
    Medium

    CVE-2012-2160

    Last Modified: 21 Nov 2024

    IBM Rational Change 5.3 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using the SUPP_TEMPLATE_FLAG parameter in a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

    Published: 27 Aug 2020
    5.3
    Medium

    CVE-2020-8927

    Last Modified: 29 May 2026

    A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.

    Published: 27 Aug 2020
    6.5
    Medium

    CVE-2019-19499

    Last Modified: 21 Nov 2024

    Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

    Published: 27 Aug 2020
    6.1
    Medium

    CVE-2020-24704

    Last Modified: 21 Nov 2024

    An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager 2.2.0, API Manager Analytics 2.2.0, API Microgateway 2.2.0, Data Analytics Server 3.2.0, Enterprise Integrator through 6.6.0, IS as Key Manager 5.5.0, Identity Server 5.5.0 and 5.8.0, Identity Server Analytics 5.5.0, and IoT Server 3.3.0 and 3.3.1.

    Published: 27 Aug 2020
    8.8
    High

    CVE-2020-24705

    Last Modified: 21 Nov 2024

    An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an attacker-controlled server if the victim submits a crafted Try It request, aka Session Hijacking. This affects API Manager through 3.1.0, API Manager Analytics 2.5.0, IS as Key Manager through 5.10.0, Identity Server through 5.10.0, Identity Server Analytics through 5.6.0, and IoT Server 3.1.0.

    Published: 27 Aug 2020
    6.1
    Medium

    CVE-2020-24706

    Last Modified: 21 Nov 2024

    An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager through 3.1.0, API Manager Analytics 2.5.0, IS as Key Manager through 5.10.0, Identity Server through 5.10.0, Identity Server Analytics through 5.6.0, and IoT Server 3.1.0.

    Published: 27 Aug 2020
    5.3
    Medium

    CVE-2020-14338

    Last Modified: 21 Nov 2024

    A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. This flaw affects all Xerces JBoss versions before 2.12.0.SP3.

    Published: 27 Aug 2020
    3.3
    Low

    CVE-2020-24654

    Last Modified: 21 Nov 2024

    In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.

    Published: 27 Aug 2020
    8.8
    High

    CVE-2020-24703

    Last Modified: 21 Nov 2024

    An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an attacker-controlled server if the victim submits a crafted Try It request, aka Session Hijacking. This affects API Manager 2.2.0, API Manager Analytics 2.2.0, API Microgateway 2.2.0, Data Analytics Server 3.2.0, Enterprise Integrator through 6.6.0, IS as Key Manager 5.5.0, Identity Server 5.5.0 and 5.8.0, Identity Server Analytics 5.5.0, and IoT Server 3.3.0 and 3.3.1.

    Published: 27 Aug 2020
    5.4
    Medium

    CVE-2020-14729

    Last Modified: 21 Nov 2024

    Vulnerability in SuiteCommerce Advanced (SCA) Sites component of Oracle NetSuite service. Supported versions that are affected are prior to 2020.1.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise NetSuite SCA. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all NetSuite SCA accessible data as well as unauthorized read access to a subset of NetSuite SCA data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:N).

    Published: 26 Aug 2020
    5.4
    Medium

    CVE-2020-14728

    Last Modified: 21 Nov 2024

    Vulnerability in the SuiteCommerce Advanced (SCA) component of Oracle NetSuite service. Supported versions that are affected are Montblanc, Vinson, Elbrus, Kilimanjaro, Aconcagua, 2018.2, 2019.1, 2019.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise NetSuite SCA. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in NetSuite SCA, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of NetSuite SCA accessible data as well as unauthorized read access to a subset of NetSuite SCA data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).

    Published: 26 Aug 2020
    8.8
    High

    CVE-2019-5321

    Last Modified: 21 Nov 2024

    Aruba Intelligent Edge Switch Series 2540, 2530, 2930F, 2930M, 2920, 5400R, and 3810M with firmware 16.08.* before 16.08.0009, 16.09.* before 16.09.0007, 16.10.* before 16.10.0003 are vulnerable to Remote Unauthorized Access in the WebUI.

    Published: 26 Aug 2020
    6.1
    Medium

    CVE-2019-5320

    Last Modified: 21 Nov 2024

    Aruba Intelligent Edge Switch Series 2540, 2530, 2930F, 2930M, 2920, 5400R, and 3810M with firmware 16.08.* before 16.08.0009, 16.09.* before 16.09.0007, 16.10.* before 16.10.0003 are vulnerable to Cross Site Scripting in the web UI, leading to injection of code.

    Published: 26 Aug 2020
    6.1
    Medium

    CVE-2020-24598

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.

    Published: 26 Aug 2020
    6.1
    Medium

    CVE-2020-24599

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks.

    Published: 26 Aug 2020
    4.3
    Medium

    CVE-2011-4820

    Last Modified: 21 Nov 2024

    IBM Rational Asset Manager 7.5 could allow a remote attacker to bypass security restrictions. An attacker could exploit this vulnerability using the UID parameter to modify another user's preferences.

    Published: 26 Aug 2020
    3.3
    Low

    CVE-2019-4695

    Last Modified: 21 Nov 2024

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 171926.

    Published: 26 Aug 2020
    5.5
    Medium

    CVE-2020-15485

    Last Modified: 21 Nov 2024

    An issue was discovered on Nescomed Multipara Monitor M1000 devices. The onboard Flash memory stores data in cleartext, without integrity protection against tampering.

    Published: 26 Aug 2020
    6.8
    Medium

    CVE-2020-15156

    Last Modified: 21 Nov 2024

    In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum. This is due to lack of CSRF validation.

    Published: 26 Aug 2020
    8.8
    High

    CVE-2019-4713

    Last Modified: 21 Nov 2024

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 172084.

    Published: 26 Aug 2020
    5.3
    Medium

    CVE-2019-4701

    Last Modified: 21 Nov 2024

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 171936.

    Published: 26 Aug 2020
    2.7
    Low

    CVE-2019-4699

    Last Modified: 21 Nov 2024

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 171931.

    Published: 26 Aug 2020
    7.5
    High

    CVE-2019-4698

    Last Modified: 21 Nov 2024

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 171929.

    Published: 26 Aug 2020
    6.5
    Medium

    CVE-2019-4697

    Last Modified: 21 Nov 2024

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 171938.

    Published: 26 Aug 2020
    9.8
    Critical

    CVE-2019-4694

    Last Modified: 21 Nov 2024

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171832.

    Published: 26 Aug 2020
    4.4
    Medium

    CVE-2019-4693

    Last Modified: 21 Nov 2024

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by a local privileged user. IBM X-Force ID: 171831.

    Published: 26 Aug 2020
    5.3
    Medium

    CVE-2019-4692

    Last Modified: 21 Nov 2024

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 171829.

    Published: 26 Aug 2020
    5.4
    Medium

    CVE-2019-4691

    Last Modified: 21 Nov 2024

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171828.

    Published: 26 Aug 2020
    7.5
    High

    CVE-2019-4689

    Last Modified: 21 Nov 2024

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 171826.

    Published: 26 Aug 2020
    4.3
    Medium

    CVE-2019-4688

    Last Modified: 21 Nov 2024

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 171825.

    Published: 26 Aug 2020
    5.3
    Medium

    CVE-2019-4686

    Last Modified: 21 Nov 2024

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 171822.

    Published: 26 Aug 2020
    7.5
    High

    CVE-2018-1501

    Last Modified: 21 Nov 2024

    IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missing security controls. IBM X-Force ID: 141226.

    Published: 26 Aug 2020
    8.8
    High

    CVE-2020-12855

    Last Modified: 21 Nov 2024

    A Host header injection vulnerability has been discovered in SecZetta NEProfile 3.3.11. Authenticated remote adversaries can poison this header resulting in an adversary controlling the execution flow for the 302 HTTP status.

    Published: 26 Aug 2020
    5.3
    Medium

    CVE-2020-24548

    Last Modified: 21 Nov 2024

    Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP ports, and provides "Cannot connect to" error messages to inform the attacker about closed ports.

    Published: 26 Aug 2020
    7.5
    High

    CVE-2020-11497

    Last Modified: 21 Nov 2024

    An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details entry step.

    Published: 26 Aug 2020
    7.5
    High

    CVE-2020-11797

    Last Modified: 21 Nov 2024

    An Authentication Bypass vulnerability in the Published Area of the web conferencing component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an unauthenticated attacker to gain access to unauthorized information due to insufficient access validation. A successful exploit could allow an attacker to access sensitive shared files.

    Published: 26 Aug 2020
    8.8
    High

    CVE-2020-12456

    Last Modified: 3 Nov 2025

    A remote code execution vulnerability in Mitel MiVoice Connect Client before 214.100.1223.0 could allow an attacker to execute arbitrary code in the chat notification window, due to improper rendering of chat messages. A successful exploit could allow an attacker to steal session cookies, perform directory traversal, and execute arbitrary scripts in the context of the Connect client.

    Published: 26 Aug 2020
    7.5
    High

    CVE-2020-13617

    Last Modified: 21 Nov 2024

    The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts.

    Published: 26 Aug 2020
    7.7
    High

    CVE-2020-15158

    Last Modified: 21 Nov 2024

    In libIEC61850 before version 1.4.3, when a message with COTP message length field with value < 4 is received an integer underflow will happen leading to heap buffer overflow. This can cause an application crash or on some platforms even the execution of remote code. If your application is used in open networks or there are untrusted nodes in the network it is highly recommend to apply the patch. This was patched with commit 033ab5b. Users of version 1.4.x should upgrade to version 1.4.3 when available. As a workaround changes of commit 033ab5b can be applied to older versions.

    Published: 26 Aug 2020
    5.9
    Medium

    CVE-2020-13767

    Last Modified: 21 Nov 2024

    The Mitel MiCollab application before 9.1.332 for iOS could allow an unauthorized user to access restricted files and folders due to insufficient access control. An exploit requires a rooted iOS device, and (if successful) could allow an attacker to gain access to sensitive information,

    Published: 26 Aug 2020
    8.1
    High

    CVE-2020-13863

    Last Modified: 21 Nov 2024

    The SAS portal of Mitel MiCollab before 9.1.3 could allow an attacker to access user data by performing a header injection in HTTP responses, due to the improper handling of input parameters. A successful exploit could allow an attacker to access user information.

    Published: 26 Aug 2020
    5.4
    Medium

    CVE-2020-23659

    Last Modified: 21 Nov 2024

    WebPort-v1.19.17121 is affected by Cross Site Scripting (XSS) on the "connections" feature.

    Published: 26 Aug 2020
    5.4
    Medium

    CVE-2020-23660

    Last Modified: 21 Nov 2024

    webTareas v2.1 is affected by Cross Site Scripting (XSS) on "Search."

    Published: 26 Aug 2020
    5.4
    Medium

    CVE-2020-23658

    Last Modified: 21 Nov 2024

    PHP-Fusion 9.03.60 is affected by Cross Site Scripting (XSS) via infusions/member_poll_panel/poll_admin.php.

    Published: 26 Aug 2020
    5.4
    Medium

    CVE-2020-23657

    Last Modified: 21 Nov 2024

    NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Configuration."

    Published: 26 Aug 2020
    5.4
    Medium

    CVE-2020-23656

    Last Modified: 21 Nov 2024

    NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Content."

    Published: 26 Aug 2020
    5.4
    Medium

    CVE-2020-23655

    Last Modified: 21 Nov 2024

    NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Configuration."

    Published: 26 Aug 2020
    5.4
    Medium

    CVE-2020-23654

    Last Modified: 21 Nov 2024

    NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) via the module "Shop."

    Published: 26 Aug 2020