CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2020-17538

    Last Modified: 24 Mar 2025

    A buffer overflow vulnerability in GetNumSameData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript from v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    9.8
    Critical

    CVE-2019-0230

    Last Modified: 21 Nov 2024

    Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.

    Published: 13 Aug 2020
    4.1
    Medium

    CVE-2020-7301

    Last Modified: 21 Nov 2024

    Cross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to trigger alerts via the file upload tab in the DLP case management section.

    Published: 12 Aug 2020
    4.6
    Medium

    CVE-2020-7300

    Last Modified: 21 Nov 2024

    Improper Authorization vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attackers to change the configuration when logged in with view only privileges via carefully constructed HTTP post messages.

    Published: 12 Aug 2020
    6.1
    Medium

    CVE-2020-17450

    Last Modified: 21 Nov 2024

    PHP-Fusion 9.03 allows XSS on the preview page.

    Published: 12 Aug 2020
    5.4
    Medium

    CVE-2020-17449

    Last Modified: 21 Nov 2024

    PHP-Fusion 9.03 allows XSS via the error_log file.

    Published: 12 Aug 2020
    6.7
    Medium

    CVE-2020-15596

    Last Modified: 21 Nov 2024

    The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a "fake" DLL file.

    Published: 12 Aug 2020
    7.5
    High

    CVE-2020-15868

    Last Modified: 21 Nov 2024

    Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control.

    Published: 12 Aug 2020
    6.1
    Medium

    CVE-2020-17362

    Last Modified: 21 Nov 2024

    search.php in the Nova Lite theme before 1.3.9 for WordPress allows Reflected XSS.

    Published: 12 Aug 2020
    —
    Unknown

    CVE-2020-16186

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 12 Aug 2020
    7.5
    High

    CVE-2020-16139

    Last Modified: 21 Nov 2024

    A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the device remotely through sending specially crafted packets. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. For more information on this, and how to upgrade, refer to the CVE’s reference information

    Published: 12 Aug 2020
    7.5
    High

    CVE-2020-16138

    Last Modified: 21 Nov 2024

    A denial-of-service issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to remotely disable the device until it is power cycled. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. For more information on this, and how to upgrade, refer to the CVE’s reference information

    Published: 12 Aug 2020
    9.8
    Critical

    CVE-2020-16137

    Last Modified: 21 Nov 2024

    A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to reset the credentials for the SSH administrative console to arbitrary values. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. For more information on this, and how to upgrade, refer to the CVE’s reference information

    Published: 12 Aug 2020
    2.8
    Low

    CVE-2020-8905

    Last Modified: 21 Nov 2024

    A buffer length validation vulnerability in Asylo versions prior to 0.6.0 allows an attacker to read data they should not have access to. The 'enc_untrusted_recvfrom' function generates a return value which is deserialized by 'MessageReader', and copied into three different 'extents'. The length of the third 'extents' is controlled by the outside world, and not verified on copy, allowing the attacker to force Asylo to copy trusted memory data into an untrusted buffer of significantly small length.. We recommend updating Asylo to version 0.6.0 or later.

    Published: 12 Aug 2020
    6.4
    Medium

    CVE-2020-8904

    Last Modified: 21 Nov 2024

    An arbitrary memory overwrite vulnerability in the trusted memory of Asylo exists in versions prior to 0.6.0. As the ecall_restore function fails to validate the range of the output_len pointer, an attacker can manipulate the tmp_output_len value and write to an arbitrary location in the trusted (enclave) memory. We recommend updating Asylo to version 0.6.0 or later.

    Published: 12 Aug 2020
    9.8
    Critical

    CVE-2020-12107

    Last Modified: 21 Nov 2024

    The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows command injection via a text field, which allow full control over this module's Operating System.

    Published: 12 Aug 2020
    9.8
    Critical

    CVE-2020-12106

    Last Modified: 21 Nov 2024

    The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative functions such as, changing credentials of the Administrator account or connect the product to a rogue access point.

    Published: 12 Aug 2020
    5.5
    Medium

    CVE-2020-17361

    Last Modified: 21 Nov 2024

    An issue was discovered in ReadyTalk Avian 1.2.0. The vm::arrayCopy method defined in classpath-common.h returns silently when a negative length is provided (instead of throwing an exception). This could result in data being lost during the copy, with varying consequences depending on the subsequent use of the destination buffer. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 12 Aug 2020
    7.8
    High

    CVE-2020-17360

    Last Modified: 21 Nov 2024

    An issue was discovered in ReadyTalk Avian 1.2.0. The vm::arrayCopy method defined in classpath-common.h contains multiple boundary checks that are performed to prevent out-of-bounds memory read/write. However, two of these boundary checks contain an integer overflow that leads to a bypass of these checks, and out-of-bounds read/write. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 12 Aug 2020
    5.3
    Medium

    CVE-2020-7374

    Last Modified: 21 Nov 2024

    Documalis Free PDF Editor version 5.7.2.26 and Documalis Free PDF Scanner version 5.7.2.122 do not appropriately validate the contents of JPEG images contained within a PDF. Attackers can exploit this vulnerability to trigger a buffer overflow on the stack and gain remote code execution as the user running the Documalis Free PDF Editor or Documalis Free PDF Scanner software.

    Published: 12 Aug 2020
    3
    Low

    CVE-2020-2035

    Last Modified: 21 Nov 2024

    When SSL/TLS Forward Proxy Decryption mode has been configured to decrypt the web transactions, the PAN-OS URL filtering feature inspects the HTTP Host and URL path headers for policy enforcement on the decrypted HTTPS web transactions but does not consider Server Name Indication (SNI) field within the TLS Client Hello handshake. This allows a compromised host in a protected network to evade any security policy that uses URL filtering on a firewall configured with SSL Decryption in the Forward Proxy mode. A malicious actor can then use this technique to evade detection of communication on the TLS handshake phase between a compromised host and a remote malicious server. This technique does not increase the risk of a host being compromised in the network. It does not impact the confidentiality or availability of a firewall. This is considered to have a low impact on the integrity of the firewall because the firewall fails to enforce a policy on certain traffic that should have been blocked. This issue does not impact the URL filtering policy enforcement on clear text or encrypted web transactions. This technique can be used only after a malicious actor has compromised a host in the protected network and the TLS/SSL Decryption feature is enabled for the traffic that the attacker controls. Palo Alto Networks is not aware of any malware that uses this technique to exfiltrate data. This issue is applicable to all current versions of PAN-OS. This issue does not impact Panorama or WF-500 appliances.

    Published: 12 Aug 2020
    10
    Critical

    CVE-2020-5415

    Last Modified: 21 Nov 2024

    Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with the same full name as another user who is granted access to a Concourse team. GitLab groups do not have this vulnerability, so GitLab users may be moved into groups which are then configured in the Concourse team.

    Published: 12 Aug 2020
    8.8
    High

    CVE-2020-17505

    Last Modified: 21 Nov 2024

    Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_peform.

    Published: 12 Aug 2020
    9.8
    Critical

    CVE-2020-17506

    Last Modified: 21 Nov 2024

    Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.

    Published: 12 Aug 2020
    5.5
    Medium

    CVE-2020-15137

    Last Modified: 21 Nov 2024

    All versions of HoRNDIS are affected by an integer overflow in the RNDIS packet parsing routines. A malicious USB device can trigger disclosure of unrelated kernel memory to userspace applications on the host, or can cause the kernel to crash. Kernel memory disclosure is especially likely on 32-bit kernels; 64-bit kernels are more likely to crash on attempted exploitation. It is not believed that kernel memory corruption is possible, or that unattended kernel memory disclosure without the collaboration of a userspace program running on the host is possible. The vulnerability is in `HoRNDIS::receivePacket`. `msg_len`, `data_ofs`, and `data_len` can be controlled by an attached USB device, and a negative value of `data_ofs` can bypass the check for `(data_ofs + data_len + 8) > msg_len`, and subsequently can cause a wild pointer copy in the `mbuf_copyback` call. The software is not maintained and no patches are planned. Users of multi-tenant systems with HoRNDIS installed should only connect trusted USB devices to their system.

    Published: 12 Aug 2020
    3.8
    Low

    CVE-2020-6653

    Last Modified: 21 Nov 2024

    Eaton's Secure connect mobile app v1.7.3 & prior stores the user login credentials in logcat file when user create or register the account on the Mobile app. A malicious app or unauthorized user can harvest the information and later on can use the information to monitor and control the user's account and associated devices.

    Published: 12 Aug 2020
    9.8
    Critical

    CVE-2020-17446

    Last Modified: 21 Nov 2024

    asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, because of access to an uninitialized pointer in the array data decoder.

    Published: 12 Aug 2020
    8.1
    High

    CVE-2020-17497

    Last Modified: 21 Nov 2024

    eapol.c in iNet wireless daemon (IWD) through 1.8 allows attackers to trigger a PTK reinstallation by retransmitting EAPOL Msg4/4.

    Published: 12 Aug 2020
    7.5
    High

    CVE-2020-13290

    Last Modified: 21 Nov 2024

    In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page

    Published: 12 Aug 2020
    8.1
    High

    CVE-2020-13291

    Last Modified: 21 Nov 2024

    In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.

    Published: 12 Aug 2020
    5.5
    Medium

    CVE-2020-13288

    Last Modified: 21 Nov 2024

    In GitLab before 13.0.12, 13.1.6, and 13.2.3, a stored XSS vulnerability exists in the CI/CD Jobs page

    Published: 12 Aug 2020
    6.1
    Medium

    CVE-2020-13278

    Last Modified: 21 Nov 2024

    Reflected Cross-Site Scripting vulnerability in Modules.php in RosarioSIS Student Information System < 6.5.1 allows remote attackers to execute arbitrary web script via embedding javascript or HTML tags in a GET request.

    Published: 12 Aug 2020
    4.3
    Medium

    CVE-2020-6310

    Last Modified: 21 Nov 2024

    Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP users, leading to Information Disclosure.

    Published: 12 Aug 2020
    7.5
    High

    CVE-2020-6309

    Last Modified: 21 Nov 2024

    SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not perform any authentication checks for a web service allowing the attacker to send several payloads and leading to complete denial of service.

    Published: 12 Aug 2020
    8.1
    High

    CVE-2020-6301

    Last Modified: 21 Nov 2024

    SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthorized attacker to read, modify and settle trips, resulting in escalation of privileges, due to Missing Authorization Check.

    Published: 12 Aug 2020
    4.8
    Medium

    CVE-2020-6300

    Last Modified: 21 Nov 2024

    SAP Business Objects Business Intelligence Platform (Central Management Console), versions- 4.2, 4.3, allows an attacker with administrator rights can use the web application to send malicious code to a different end user (victim), as it does not sufficiently encode user-controlled inputs for RecycleBin, resulting in Stored Cross-Site Scripting (XSS) vulnerability.

    Published: 12 Aug 2020
    4.3
    Medium

    CVE-2020-6299

    Last Modified: 21 Nov 2024

    SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to access the list of users in the given system using value help, leading to Information Disclosure.

    Published: 12 Aug 2020
    8.1
    High

    CVE-2020-6298

    Last Modified: 21 Nov 2024

    SAP Banking Services (Generic Market Data), versions - 400, 450, 500, allows an unauthorized user to display protected Business Partner Generic Market Data (GMD) and change related GMD key figure values, due to Missing Authorization Check.

    Published: 12 Aug 2020
    4.4
    Medium

    CVE-2020-6297

    Last Modified: 21 Nov 2024

    Under certain conditions the upgrade of SAP Data Hub 2.7 to SAP Data Intelligence, version - 3.0, allows an attacker to access confidential system configuration information, that should otherwise be restricted, leading to Information Disclosure.

    Published: 12 Aug 2020
    8.8
    High

    CVE-2020-6296

    Last Modified: 21 Nov 2024

    SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application.

    Published: 12 Aug 2020
    7.8
    High

    CVE-2020-6295

    Last Modified: 21 Nov 2024

    Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensitive and confidential information through publicly readable installation log files leading to a compromise of the installed Cockpit. This compromise could enable the attacker to view, modify and/or make unavailable any data associated with the Cockpit, leading to Information Disclosure.

    Published: 12 Aug 2020
    9.1
    Critical

    CVE-2020-6294

    Last Modified: 21 Nov 2024

    Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for functionalities that require user identity.

    Published: 12 Aug 2020
    6.5
    Medium

    CVE-2020-2235

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows attackers to connect to an attacker-specified JDBC URL using attacker-specified credentials IDs obtained through another method, potentially capturing credentials stored in Jenkins.

    Published: 12 Aug 2020
    5.4
    Medium

    CVE-2020-2236

    Last Modified: 21 Nov 2024

    Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Run/Update permission.

    Published: 12 Aug 2020
    4.3
    Medium

    CVE-2020-2237

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Flaky Test Handler Plugin 1.0.4 and earlier allows attackers to rebuild a project at a previous git revision.

    Published: 12 Aug 2020
    6.5
    Medium

    CVE-2020-2234

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to connect to an attacker-specified JDBC URL using attacker-specified credentials IDs obtained through another method, potentially capturing credentials stored in Jenkins.

    Published: 12 Aug 2020
    6.5
    Medium

    CVE-2020-2233

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

    Published: 12 Aug 2020
    7.5
    High

    CVE-2020-2232

    Last Modified: 21 Nov 2024

    Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form, potentially resulting in its exposure.

    Published: 12 Aug 2020
    6.5
    Medium

    CVE-2020-6293

    Last Modified: 21 Nov 2024

    SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but the impact is limited to the files themselves and is restricted by other policies such as access control lists and other upload file size restrictions, leading to Unrestricted File Upload.

    Published: 12 Aug 2020
    9
    Critical

    CVE-2020-6284

    Last Modified: 21 Nov 2024

    SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privileges. If the accessing user has administrative privileges, then the execution of the script content could result in complete compromise of system confidentiality, integrity and availability, leading to Stored Cross Site Scripting.

    Published: 12 Aug 2020