CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2020-4631

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned access to everyone with full control permissions, which could allow a local user to cause interruption of the service operations. IBM X-Force ID: 185372.

    Published: 4 Aug 2020
    5.4
    Medium

    CVE-2020-4542

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 183046.

    Published: 4 Aug 2020
    5.4
    Medium

    CVE-2020-4525

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182435.

    Published: 4 Aug 2020
    9.8
    Critical

    CVE-2020-4459

    Last Modified: 21 Nov 2024

    IBM Security Verify Access 10.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 181395.

    Published: 4 Aug 2020
    4.3
    Medium

    CVE-2020-4410

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to send a specially crafted HTTP GET request to read attachments on the server that they should not have access to. IBM X-Force ID: 179539.

    Published: 4 Aug 2020
    5.4
    Medium

    CVE-2020-4396

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 179359.

    Published: 4 Aug 2020
    7.8
    High

    CVE-2020-7823

    Last Modified: 21 Nov 2024

    DaviewIndy has a Memory corruption vulnerability, triggered when the user opens a malformed image file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.

    Published: 4 Aug 2020
    7.8
    High

    CVE-2020-7822

    Last Modified: 21 Nov 2024

    DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed image file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.

    Published: 4 Aug 2020
    7.4
    High

    CVE-2020-6012

    Last Modified: 21 Nov 2024

    ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links. This allows an unprivileged user to enable escalation of privilege via local access.

    Published: 4 Aug 2020
    8.8
    High

    CVE-2020-15467

    Last Modified: 21 Nov 2024

    The administrative interface of Cohesive Networks vns3:vpn appliances before version 4.11.1 is vulnerable to authenticated remote code execution leading to server compromise.

    Published: 4 Aug 2020
    7.8
    High

    CVE-2019-20001

    Last Modified: 21 Nov 2024

    An issue was discovered in RICOH Streamline NX Client Tool and RICOH Streamline NX PC Client that allows attackers to escalate local privileges.

    Published: 4 Aug 2020
    5.3
    Medium

    CVE-2020-10775

    Last Modified: 21 Nov 2024

    An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in their browser, the critical part of the URL is no longer visible. The highest threat from this vulnerability is on confidentiality.

    Published: 4 Aug 2020
    7.8
    High

    CVE-2020-5617

    Last Modified: 21 Nov 2024

    Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unauthorized privileges and modify/obtain sensitive information or perform unintended operations via unspecified vectors.

    Published: 4 Aug 2020
    9.8
    Critical

    CVE-2020-5616

    Last Modified: 21 Nov 2024

    [Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01] free edition ver1.0.1 and earlier, [Telop01] free edition ver1.0.0, [Gallery01] free edition ver1.0.3 and earlier, [CalendarForm01] free edition ver1.0.3 and earlier, and [Link01] free edition ver1.0.0 allows remote attackers to bypass authentication and log in to the product with administrative privileges via unspecified vectors.

    Published: 4 Aug 2020
    8.8
    High

    CVE-2020-5615

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in [Calendar01] free edition ver1.0.0 and [Calendar02] free edition ver1.0.0 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 4 Aug 2020
    9.3
    Critical

    CVE-2020-15708

    Last Modified: 21 Nov 2024

    Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite arbitrary files or execute arbitrary code.

    Published: 4 Aug 2020
    6.5
    Medium

    CVE-2020-28241

    Last Modified: 21 Nov 2024

    libmaxminddb before 1.4.3 has a heap-based buffer over-read in dump_entry_data_list in maxminddb.c.

    Published: 4 Aug 2020
    8.8
    High

    CVE-2021-39537

    Last Modified: 21 Nov 2024

    An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.

    Published: 4 Aug 2020
    6.1
    Medium

    CVE-2020-11583

    Last Modified: 21 Nov 2024

    A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.

    Published: 3 Aug 2020
    6.1
    Medium

    CVE-2020-11584

    Last Modified: 21 Nov 2024

    A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.

    Published: 3 Aug 2020
    7.5
    High

    CVE-2020-5771

    Last Modified: 21 Nov 2024

    Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious backup archive.

    Published: 3 Aug 2020
    8.8
    High

    CVE-2020-5770

    Last Modified: 21 Nov 2024

    Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

    Published: 3 Aug 2020
    8.8
    High

    CVE-2020-5773

    Last Modified: 21 Nov 2024

    Improper Access Control in Teltonika firmware TRB2_R_00.02.04.01 allows a low privileged user to perform unauthorized write operations.

    Published: 3 Aug 2020
    7.5
    High

    CVE-2020-5772

    Last Modified: 21 Nov 2024

    Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious package file.

    Published: 3 Aug 2020
    7.8
    High

    CVE-2020-8574

    Last Modified: 21 Nov 2024

    Active IQ Unified Manager for Linux versions prior to 9.6 ship with the Java Management Extension Remote Method Invocation (JMX RMI) service enabled allowing unauthorized code execution to local users.

    Published: 3 Aug 2020
    4.4
    Medium

    CVE-2020-8575

    Last Modified: 21 Nov 2024

    Active IQ Unified Manager for VMware vSphere and Windows versions prior to 9.5 are susceptible to a vulnerability which allows administrative users to cause Denial of Service (DoS).

    Published: 3 Aug 2020
    6.1
    Medium

    CVE-2020-16131

    Last Modified: 21 Nov 2024

    Tiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.

    Published: 3 Aug 2020
    5.3
    Medium

    CVE-2020-12739

    Last Modified: 21 Nov 2024

    A denial-of-service vulnerability in the Fanuc i Series CNC (0i-MD and 0i Mate-MD) could allow an unauthenticated, remote attacker to cause an affected CNC to become inaccessible to other devices.

    Published: 3 Aug 2020
    6.1
    Medium

    CVE-2020-13820

    Last Modified: 21 Nov 2024

    Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.

    Published: 3 Aug 2020
    9.1
    Critical

    CVE-2020-16271

    Last Modified: 21 Nov 2024

    The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 generates insufficiently random numbers, which allows remote attackers to read and modify data in the KeePass database via a WebSocket connection.

    Published: 3 Aug 2020
    9.1
    Critical

    CVE-2020-16272

    Last Modified: 21 Nov 2024

    The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 is missing validation for a client-provided parameter, which allows remote attackers to read and modify data in the KeePass database via an A=0 WebSocket connection.

    Published: 3 Aug 2020
    5.5
    Medium

    CVE-2020-16269

    Last Modified: 21 Nov 2024

    radare2 4.5.0 misparses DWARF information in executable files, causing a segmentation fault in parse_typedef in type_dwarf.c via a malformed DW_AT_name in the .debug_info section.

    Published: 3 Aug 2020
    6.1
    Medium

    CVE-2015-9549

    Last Modified: 21 Nov 2024

    A reflected Cross-site Scripting (XSS) vulnerability exists in OcPortal 9.0.20 via the OCF_EMOTICON_CELL.tpl FIELD_NAME field to data/emoticons.php.

    Published: 3 Aug 2020
    7.1
    High

    CVE-2020-14296

    Last Modified: 21 Nov 2024

    Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker could scan and attack systems from the internal network which are not normally accessible.

    Published: 3 Aug 2020
    6.3
    Medium

    CVE-2020-10780

    Last Modified: 21 Nov 2024

    Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula executes, triggering any number of possible events. While this is strictly not an flaw that affects the application directly, attackers could use the loosely validated parameters to trigger several attack possibilities.

    Published: 3 Aug 2020
    9.1
    Critical

    CVE-2020-14324

    Last Modified: 21 Nov 2024

    A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerability can be exploited by authenticated attacker while setuping conversion host through Infrastructure Migration Solution. This flaw allows attacker to execute arbitrary commands on CloudForms server.

    Published: 3 Aug 2020
    8.3
    High

    CVE-2020-10783

    Last Modified: 21 Nov 2024

    Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group can perform actions restricted only to EVM-Super-administrator group, leads to, exporting or importing administrator files.

    Published: 3 Aug 2020
    5.4
    Medium

    CVE-2020-10777

    Last Modified: 21 Nov 2024

    A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms.

    Published: 3 Aug 2020
    6
    Medium

    CVE-2020-10778

    Last Modified: 21 Nov 2024

    In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate the expected behavior.

    Published: 3 Aug 2020
    6.5
    Medium

    CVE-2020-10779

    Last Modified: 21 Nov 2024

    Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right criteria, it is possible to access some sensitive data within the CloudForms.

    Published: 3 Aug 2020
    9.1
    Critical

    CVE-2020-14325

    Last Modified: 21 Nov 2024

    Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious attacker to create existent and non-existent role-based access control user, with groups and roles. With a selected group of EvmGroup-super_administrator, an attacker can perform any API request as a super administrator.

    Published: 3 Aug 2020
    7.8
    High

    CVE-2019-19455

    Last Modified: 21 Nov 2024

    Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in / usr / local / WowzaStreamingEngine / manager / bin / in the Linux version of the server by writing arbitrary commands in any file and execute them as root. This issue was resolved in Wowza Streaming Engine 4.8.5.

    Published: 3 Aug 2020
    5.4
    Medium

    CVE-2019-19453

    Last Modified: 21 Nov 2024

    Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2). An authenticated user, with access to the proxy license editing is able to insert a malicious payload that will be triggered in the main page of server settings. This issue was resolved in Wowza Streaming Engine 4.8.5.

    Published: 3 Aug 2020
    6.1
    Medium

    CVE-2020-4560

    Last Modified: 21 Nov 2024

    IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 3 Aug 2020
    7.8
    High

    CVE-2020-4554

    Last Modified: 21 Nov 2024

    IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183322.

    Published: 3 Aug 2020
    7.8
    High

    CVE-2020-4553

    Last Modified: 21 Nov 2024

    IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183321.

    Published: 3 Aug 2020
    7.8
    High

    CVE-2020-4552

    Last Modified: 21 Nov 2024

    IBM i2 Analyst Notebook 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183320.

    Published: 3 Aug 2020
    7.8
    High

    CVE-2020-4551

    Last Modified: 21 Nov 2024

    IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183319.

    Published: 3 Aug 2020
    7.8
    High

    CVE-2020-4550

    Last Modified: 21 Nov 2024

    IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183318.

    Published: 3 Aug 2020
    7.8
    High

    CVE-2020-4549

    Last Modified: 21 Nov 2024

    IBM i2 Analyst Notebook 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183317.

    Published: 3 Aug 2020