CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2020-13285

    Last Modified: 21 Nov 2024

    For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting (XSS) vulnerability exists in the issue reference number tooltip.

    Published: 13 Aug 2020
    7.3
    High

    CVE-2020-13283

    Last Modified: 21 Nov 2024

    For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issues list via milestone title.

    Published: 13 Aug 2020
    3.1
    Low

    CVE-2020-13282

    Last Modified: 21 Nov 2024

    For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.

    Published: 13 Aug 2020
    9.8
    Critical

    CVE-2019-16374

    Last Modified: 21 Nov 2024

    Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, followed by the * character, to bypass access control.

    Published: 13 Aug 2020
    9.8
    Critical

    CVE-2020-17463

    Last Modified: 7 Nov 2025

    FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

    Published: 13 Aug 2020
    8.6
    High

    CVE-2020-16087

    Last Modified: 21 Nov 2024

    An issue was discovered in Zalo.exe in VNG Zalo Desktop 19.8.1.0. An attacker can run arbitrary commands on a remote Windows machine running the Zalo client by sending the user of the device a crafted file.

    Published: 13 Aug 2020
    9.8
    Critical

    CVE-2020-4589

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 184585.

    Published: 13 Aug 2020
    4.3
    Medium

    CVE-2019-4582

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 167288.

    Published: 13 Aug 2020
    6.5
    Medium

    CVE-2019-14620

    Last Modified: 21 Nov 2024

    Insufficient control flow management for some Intel(R) Wireless Bluetooth(R) products may allow an unprivileged user to potentially enable denial of service via adjacent access.

    Published: 13 Aug 2020
    4.4
    Medium

    CVE-2020-0553

    Last Modified: 21 Nov 2024

    Out-of-bounds read in kernel mode driver for some Intel(R) Wireless Bluetooth(R) products on Windows* 10, may allow a privileged user to potentially enable information disclosure via local access.

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-0555

    Last Modified: 21 Nov 2024

    Improper input validation for some Intel(R) Wireless Bluetooth(R) products may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    7
    High

    CVE-2020-0554

    Last Modified: 21 Nov 2024

    Race condition in software installer for some Intel(R) Wireless Bluetooth(R) products on Windows* 7, 8.1 and 10 may allow an unprivileged user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-0559

    Last Modified: 21 Nov 2024

    Insecure inherited permissions in some Intel(R) PROSet/Wireless WiFi products on Windows* 7 and 8.1 before version 21.40.5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    8.2
    High

    CVE-2020-12299

    Last Modified: 21 Nov 2024

    Improper input validation in BIOS firmware for Intel(R) Server Board Families S2600ST, S2600BP and S2600WF may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    8.2
    High

    CVE-2020-12301

    Last Modified: 21 Nov 2024

    Improper initialization in BIOS firmware for Intel(R) Server Board Families S2600ST, S2600BP and S2600WF may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    8.2
    High

    CVE-2020-12300

    Last Modified: 21 Nov 2024

    Uninitialized pointer in BIOS firmware for Intel(R) Server Board Families S2600CW, S2600KP, S2600TP, and S2600WT may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-8683

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in system driver for some Intel(R) Graphics Drivers before version 15.33.50.5129 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-8682

    Last Modified: 21 Nov 2024

    Out of bounds read in system driver for some Intel(R) Graphics Drivers before version 15.33.50.5129 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-0512

    Last Modified: 21 Nov 2024

    Uncaught exception in the system driver for some Intel(R) Graphics Drivers before version 15.33.50.5129 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-8679

    Last Modified: 21 Nov 2024

    Out-of-bounds write in Kernel Mode Driver for some Intel(R) Graphics Drivers before version 26.20.100.7755 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 13 Aug 2020
    5.2
    Medium

    CVE-2020-7307

    Last Modified: 21 Nov 2024

    Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the RiskDB username and password via unprotected log files containing plain text credentials.

    Published: 13 Aug 2020
    7
    High

    CVE-2020-8680

    Last Modified: 21 Nov 2024

    Race condition in some Intel(R) Graphics Drivers before version 15.40.45.5126 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-8681

    Last Modified: 21 Nov 2024

    Out of bounds write in system driver for some Intel(R) Graphics Drivers before version 15.33.50.5129 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-0513

    Last Modified: 21 Nov 2024

    Out of bounds write for some Intel(R) Graphics Drivers before version 15.33.50.5129 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-0510

    Last Modified: 21 Nov 2024

    Out of bounds read in some Intel(R) Graphics Drivers before versions 15.45.31.5127 and 15.40.45.5126 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    6.7
    Medium

    CVE-2020-8684

    Last Modified: 21 Nov 2024

    Improper access control in firmware for Intel(R) PAC with Arria(R) 10 GX FPGA before Intel Acceleration Stack version 1.2.1 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    4.4
    Medium

    CVE-2020-8685

    Last Modified: 21 Nov 2024

    Improper authentication in subsystem for Intel (R) LED Manager for NUC before version 1.2.3 may allow privileged user to potentially enable denial of service via local access.

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-8687

    Last Modified: 21 Nov 2024

    Uncontrolled search path in the installer for Intel(R) RSTe Software RAID Driver for the Intel(R) Server Board M10JNP2SB before version 4.7.0.1119 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    7.5
    High

    CVE-2020-8688

    Last Modified: 21 Nov 2024

    Improper input validation in the Intel(R) RAID Web Console 3 for Windows* may allow an unauthenticated user to potentially enable denial of service via network access.

    Published: 13 Aug 2020
    6.5
    Medium

    CVE-2020-8689

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in the Intel(R) Wireless for Open Source before version 1.5 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-8720

    Last Modified: 21 Nov 2024

    Buffer overflow in a subsystem for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow a privileged user to potentially enable denial of service via local access.

    Published: 13 Aug 2020
    5.2
    Medium

    CVE-2020-7306

    Last Modified: 21 Nov 2024

    Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plain text

    Published: 13 Aug 2020
    6.7
    Medium

    CVE-2020-7305

    Last Modified: 21 Nov 2024

    Privilege escalation vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows a low privileged remote attacker to create new rule sets via incorrect validation of user credentials.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-8717

    Last Modified: 21 Nov 2024

    Improper input validation in a subsystem for some Intel Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 13 Aug 2020
    7.6
    High

    CVE-2020-7304

    Last Modified: 21 Nov 2024

    Cross site request forgery vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attacker to embed a CRSF script via adding a new label.

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-8714

    Last Modified: 21 Nov 2024

    Improper authentication for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-8716

    Last Modified: 21 Nov 2024

    Improper access control for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-8715

    Last Modified: 21 Nov 2024

    Invalid pointer for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable denial of service via local access.

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-8729

    Last Modified: 21 Nov 2024

    Buffer copy without checking size of input for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    8.8
    High

    CVE-2020-8706

    Last Modified: 21 Nov 2024

    Buffer overflow in a daemon for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 13 Aug 2020
    4.1
    Medium

    CVE-2020-7303

    Last Modified: 21 Nov 2024

    Cross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote user to trigger scripts to run in a user's browser via adding a new label.

    Published: 13 Aug 2020
    8.8
    High

    CVE-2020-8713

    Last Modified: 21 Nov 2024

    Improper authentication for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 13 Aug 2020
    6.3
    Medium

    CVE-2020-8723

    Last Modified: 21 Nov 2024

    Cross-site scripting for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 13 Aug 2020
    8.8
    High

    CVE-2020-8709

    Last Modified: 21 Nov 2024

    Improper authentication in socket services for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 13 Aug 2020
    8.8
    High

    CVE-2020-8732

    Last Modified: 21 Nov 2024

    Heap-based buffer overflow in the firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 13 Aug 2020
    8.2
    High

    CVE-2020-8722

    Last Modified: 21 Nov 2024

    Buffer overflow in a subsystem for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    5.4
    Medium

    CVE-2020-7302

    Last Modified: 21 Nov 2024

    Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to upload malicious files to the DLP case management section via lack of sanity checking.

    Published: 13 Aug 2020
    8.8
    High

    CVE-2020-8718

    Last Modified: 21 Nov 2024

    Buffer overflow in a subsystem for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-8712

    Last Modified: 21 Nov 2024

    Buffer overflow in a verification process for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.45 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    6.7
    Medium

    CVE-2020-8711

    Last Modified: 21 Nov 2024

    Improper access control in the bootloader for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.45 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020