CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2020-13293

    Last Modified: 21 Nov 2024

    In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.

    Published: 10 Aug 2020
    7.8
    High

    CVE-2020-6070

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A specially crafted f2fs file can cause a logic flaw and out-of-bounds heap operations, resulting in code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 10 Aug 2020
    8.8
    High

    CVE-2020-6145

    Last Modified: 21 Nov 2024

    An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 10 Aug 2020
    6.1
    Medium

    CVE-2020-4541

    Last Modified: 21 Nov 2024

    IBM Jazz Reporting Service 7.0 and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183039.

    Published: 10 Aug 2020
    6.1
    Medium

    CVE-2020-4539

    Last Modified: 21 Nov 2024

    IBM Jazz Reporting Service 6.0.2, 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 10 Aug 2020
    6.1
    Medium

    CVE-2020-4533

    Last Modified: 21 Nov 2024

    IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182717.

    Published: 10 Aug 2020
    5.7
    Medium

    CVE-2020-12781

    Last Modified: 21 Nov 2024

    Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.

    Published: 10 Aug 2020
    7.5
    High

    CVE-2020-12780

    Last Modified: 21 Nov 2024

    A security misconfiguration exists in Combodo iTop, which can expose sensitive information.

    Published: 10 Aug 2020
    6.8
    Medium

    CVE-2020-12779

    Last Modified: 21 Nov 2024

    Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with malicious script.

    Published: 10 Aug 2020
    7.4
    High

    CVE-2020-12778

    Last Modified: 21 Nov 2024

    Combodo iTop does not validate inputted parameters, attackers can inject malicious commands and launch XSS attack.

    Published: 10 Aug 2020
    7.5
    High

    CVE-2020-12777

    Last Modified: 21 Nov 2024

    A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthorized attacker to inject command and disclose system information.

    Published: 10 Aug 2020
    8.8
    High

    CVE-2020-6542

    Last Modified: 21 Nov 2024

    Use after free in ANGLE in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Aug 2020
    8.8
    High

    CVE-2020-6544

    Last Modified: 21 Nov 2024

    Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Aug 2020
    8.8
    High

    CVE-2020-6550

    Last Modified: 21 Nov 2024

    Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Aug 2020
    8.8
    High

    CVE-2020-6551

    Last Modified: 21 Nov 2024

    Use after free in WebXR in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Aug 2020
    8.8
    High

    CVE-2020-6545

    Last Modified: 21 Nov 2024

    Use after free in audio in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Aug 2020
    7.8
    High

    CVE-2020-6546

    Last Modified: 21 Nov 2024

    Inappropriate implementation in installer in Google Chrome prior to 84.0.4147.125 allowed a local attacker to potentially elevate privilege via a crafted filesystem.

    Published: 10 Aug 2020
    6.5
    Medium

    CVE-2020-6547

    Last Modified: 21 Nov 2024

    Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page.

    Published: 10 Aug 2020
    8.8
    High

    CVE-2020-6548

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.125 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Aug 2020
    8.8
    High

    CVE-2020-6549

    Last Modified: 21 Nov 2024

    Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Aug 2020
    8.8
    High

    CVE-2020-6552

    Last Modified: 21 Nov 2024

    Use after free in Blink in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Aug 2020
    8.8
    High

    CVE-2020-6553

    Last Modified: 21 Nov 2024

    Use after free in offline mode in Google Chrome on iOS prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Aug 2020
    8.6
    High

    CVE-2020-6554

    Last Modified: 21 Nov 2024

    Use after free in extensions in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.

    Published: 10 Aug 2020
    7.6
    High

    CVE-2020-6555

    Last Modified: 21 Nov 2024

    Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 10 Aug 2020
    5.5
    Medium

    CVE-2021-32280

    Last Modified: 21 Nov 2024

    An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() located in trans_spline.c. It allows an attacker to cause Denial of Service. The fixed version of fig2dev is 3.2.8.

    Published: 10 Aug 2020
    8.8
    High

    CVE-2020-6543

    Last Modified: 21 Nov 2024

    Use after free in task scheduling in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Aug 2020
    4.8
    Medium

    CVE-2020-17451

    Last Modified: 21 Nov 2024

    flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title, page_content, or page_extracontent parameter, or the acp/acp.php?tn=system&sub=sys_pref prefs_pagename, prefs_pagetitle, or prefs_pagesubtitle parameter.

    Published: 9 Aug 2020
    7.2
    High

    CVE-2020-17452

    Last Modified: 21 Nov 2024

    flatCore before 1.5.7 allows upload and execution of a .php file by an admin.

    Published: 9 Aug 2020
    —
    Unknown

    CVE-2020-17447

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-15139. Reason: This candidate is a duplicate of CVE-2020-15139. Notes: All CVE users should reference CVE-2020-15139 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 9 Aug 2020
    5.8
    Medium

    CVE-2020-16248

    Last Modified: 21 Nov 2024

    Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability

    Published: 9 Aug 2020
    7.5
    High

    CVE-2019-19704

    Last Modified: 21 Nov 2024

    In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm.

    Published: 8 Aug 2020
    6.1
    Medium

    CVE-2020-15830

    Last Modified: 21 Nov 2024

    JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.

    Published: 8 Aug 2020
    6.1
    Medium

    CVE-2020-15831

    Last Modified: 21 Nov 2024

    JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.

    Published: 8 Aug 2020
    6.5
    Medium

    CVE-2020-15828

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2020.1.1, project parameter values can be retrieved by a user without appropriate permissions.

    Published: 8 Aug 2020
    5.3
    Medium

    CVE-2020-15829

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.

    Published: 8 Aug 2020
    8.8
    High

    CVE-2020-15825

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges.

    Published: 8 Aug 2020
    4.3
    Medium

    CVE-2020-15826

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.

    Published: 8 Aug 2020
    7.5
    High

    CVE-2020-15827

    Last Modified: 21 Nov 2024

    In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.

    Published: 8 Aug 2020
    7.5
    High

    CVE-2020-15823

    Last Modified: 21 Nov 2024

    JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.

    Published: 8 Aug 2020
    6.5
    Medium

    CVE-2020-15821

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.

    Published: 8 Aug 2020
    5.3
    Medium

    CVE-2020-15820

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence.

    Published: 8 Aug 2020
    5.3
    Medium

    CVE-2020-15819

    Last Modified: 21 Nov 2024

    JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.

    Published: 8 Aug 2020
    8.8
    High

    CVE-2020-15817

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues.

    Published: 8 Aug 2020
    5.3
    Medium

    CVE-2020-15818

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence.

    Published: 8 Aug 2020
    6.1
    Medium

    CVE-2020-24301

    Last Modified: 21 Nov 2024

    Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability in this module, allowing arbitrary JavaScript to be executed in the user's browser. The impact of this vulnerability is believed to be low, as this module is intended for testing and not believed to be widely used for any production purposes.

    Published: 8 Aug 2020
    6.5
    Medium

    CVE-2020-15065

    Last Modified: 21 Nov 2024

    DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to denial-of-service the device via long input values.

    Published: 7 Aug 2020
    4.3
    Medium

    CVE-2020-15064

    Last Modified: 21 Nov 2024

    DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.

    Published: 7 Aug 2020
    8.8
    High

    CVE-2020-15063

    Last Modified: 21 Nov 2024

    DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.

    Published: 7 Aug 2020
    8.8
    High

    CVE-2020-15062

    Last Modified: 21 Nov 2024

    DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.

    Published: 7 Aug 2020
    6.5
    Medium

    CVE-2020-15061

    Last Modified: 21 Nov 2024

    Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to denial-of-service the device via long input values.

    Published: 7 Aug 2020