CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-8178

    Last Modified: 21 Nov 2024

    Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks.

    Published: 15 Jul 2020
    7.5
    High

    CVE-2020-15572

    Last Modified: 21 Nov 2024

    Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor instances built to use Mozilla Network Security Services (NSS), aka TROVE-2020-001.

    Published: 15 Jul 2020
    6.3
    Medium

    CVE-2020-15700

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability.

    Published: 15 Jul 2020
    5.3
    Medium

    CVE-2020-15699

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration.

    Published: 15 Jul 2020
    5.3
    Medium

    CVE-2020-15698

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Redis or proxy credentials

    Published: 15 Jul 2020
    4.3
    Medium

    CVE-2020-15697

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users.

    Published: 15 Jul 2020
    6.1
    Medium

    CVE-2020-15696

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.

    Published: 15 Jul 2020
    6.3
    Medium

    CVE-2020-15695

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability.

    Published: 15 Jul 2020
    6.1
    Medium

    CVE-2020-9496

    Last Modified: 21 Nov 2024

    XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03

    Published: 15 Jul 2020
    5.3
    Medium

    CVE-2020-13923

    Last Modified: 21 Nov 2024

    IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04

    Published: 15 Jul 2020
    4.3
    Medium

    CVE-2020-7292

    Last Modified: 21 Nov 2024

    Inappropriate Encoding for output context vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows a remote attacker to cause MWG to return an ambiguous redirect response via getting a user to click on a malicious URL.

    Published: 15 Jul 2020
    4.4
    Medium

    CVE-2020-4100

    Last Modified: 21 Nov 2024

    "HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which components of the application should not be loaded by default when the application is started. Typically, core components and additional dependencies are loaded natively at runtime; however, dynamically loaded components are only loaded as they are specifically requested. While this can have a positive impact on performance, or grant additional functionality (for example, a non-invasive update feature), it can also open the application to loading unintended code if not implemented properly."

    Published: 15 Jul 2020
    9.8
    Critical

    CVE-2020-14511

    Last Modified: 21 Nov 2024

    Malicious operation of the crafted web browser cookie may cause a stack-based buffer overflow in the system web server on the EDR-G902 and EDR-G903 Series Routers (versions prior to 5.4).

    Published: 15 Jul 2020
    5.4
    Medium

    CVE-2020-5765

    Last Modified: 21 Nov 2024

    Nessus 8.10.0 and earlier were found to contain a Stored XSS vulnerability due to improper validation of input during scan configuration. An authenticated, remote attacker could potentially exploit this vulnerability to execute arbitrary code in a user's session. Tenable has implemented additional input validation mechanisms to correct this issue in Nessus 8.11.0.

    Published: 15 Jul 2020
    9.8
    Critical

    CVE-2020-14501

    Last Modified: 21 Nov 2024

    Advantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-306) issue. Successful exploitation of this vulnerability may allow an attacker to obtain the information of the user table, including the administrator credentials in plain text. An attacker may also delete the administrator account.

    Published: 15 Jul 2020
    9.8
    Critical

    CVE-2020-14503

    Last Modified: 21 Nov 2024

    Advantech iView, versions 5.6 and prior, has an improper input validation vulnerability. Successful exploitation of this vulnerability could allow an attacker to remotely execute arbitrary code.

    Published: 15 Jul 2020
    7.5
    High

    CVE-2020-14499

    Last Modified: 21 Nov 2024

    Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this vulnerability may allow an attacker to obtain all user accounts credentials.

    Published: 15 Jul 2020
    9.8
    Critical

    CVE-2020-14505

    Last Modified: 21 Nov 2024

    Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to send a HTTP GET or POST request that creates a command string without any validation. The attacker may then remotely execute code.

    Published: 15 Jul 2020
    9.8
    Critical

    CVE-2020-14497

    Last Modified: 21 Nov 2024

    Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled string in the construction of SQL queries. An attacker could extract user credentials, read or modify information, and remotely execute code.

    Published: 15 Jul 2020
    9.8
    Critical

    CVE-2020-14507

    Last Modified: 21 Nov 2024

    Advantech iView, versions 5.6 and prior, is vulnerable to multiple path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.

    Published: 15 Jul 2020
    7.1
    High

    CVE-2019-17637

    Last Modified: 21 Nov 2024

    In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.

    Published: 15 Jul 2020
    9.8
    Critical

    CVE-2020-15801

    Last Modified: 21 Nov 2024

    In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The <executable-name>._pth file (e.g., the python._pth file) is not affected.

    Published: 15 Jul 2020
    5.3
    Medium

    CVE-2020-24371

    Last Modified: 21 Nov 2024

    lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage.

    Published: 15 Jul 2020
    5.5
    Medium

    CVE-2020-8557

    Last Modified: 21 Nov 2024

    The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet eviction manager when calculating ephemeral storage usage by a pod. If a pod writes a large amount of data to the /etc/hosts file, it could fill the storage space of the node and cause the node to fail.

    Published: 15 Jul 2020
    5.4
    Medium

    CVE-2020-2220

    Last Modified: 21 Nov 2024

    Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.

    Published: 15 Jul 2020
    5.4
    Medium

    CVE-2020-2221

    Last Modified: 21 Nov 2024

    Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.

    Published: 15 Jul 2020
    5.4
    Medium

    CVE-2020-2222

    Last Modified: 21 Nov 2024

    Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored cross-site scripting vulnerability.

    Published: 15 Jul 2020
    5.4
    Medium

    CVE-2020-2223

    Last Modified: 21 Nov 2024

    Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of links to downstream jobs displayed in the build console page, resulting in a stored cross-site scripting vulnerability.

    Published: 15 Jul 2020
    5.4
    Medium

    CVE-2020-2225

    Last Modified: 21 Nov 2024

    Jenkins Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes, resulting in a stored cross-site scripting vulnerability.

    Published: 15 Jul 2020
    5.4
    Medium

    CVE-2020-2226

    Last Modified: 21 Nov 2024

    Jenkins Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in the configuration, resulting in a stored cross-site scripting vulnerability.

    Published: 15 Jul 2020
    4.1
    Medium

    CVE-2020-2978

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle Database - Enterprise Edition component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having DBA role account privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition. While the vulnerability is in Oracle Database - Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Database - Enterprise Edition accessible data. CVSS 3.1 Base Score 4.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N).

    Published: 15 Jul 2020
    5.4
    Medium

    CVE-2020-2224

    Last Modified: 21 Nov 2024

    Jenkins Matrix Project Plugin 1.16 and earlier does not escape the node names shown in tooltips on the overview page of builds with a single axis, resulting in a stored cross-site scripting vulnerability.

    Published: 15 Jul 2020
    6.4
    Medium

    CVE-2020-8559

    Last Modified: 21 Nov 2024

    The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.

    Published: 15 Jul 2020
    7.5
    High

    CVE-2020-1469

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists when the .NET implementation of Bond improperly parses input, aka 'Bond Denial of Service Vulnerability'.

    Published: 14 Jul 2020
    8.8
    High

    CVE-2020-1481

    Last Modified: 20 Aug 2025

    A remote code execution vulnerability exists in the ESLint extension for Visual Studio Code when it validates source code after opening a project, aka 'Visual Studio Code ESLint Extention Remote Code Execution Vulnerability'.

    Published: 14 Jul 2020
    6.5
    Medium

    CVE-2020-1468

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.

    Published: 14 Jul 2020
    7.8
    High

    CVE-2020-1463

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the SharedStream Library handles objects in memory, aka 'Windows SharedStream Library Elevation of Privilege Vulnerability'.

    Published: 14 Jul 2020
    7.8
    High

    CVE-2020-1465

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Microsoft OneDrive that allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft OneDrive Elevation of Privilege Vulnerability'.

    Published: 14 Jul 2020
    7.1
    High

    CVE-2020-1461

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.

    Published: 14 Jul 2020
    4.3
    Medium

    CVE-2020-1462

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based), aka 'Skype for Business via Microsoft Edge (EdgeHTML-based) Information Disclosure Vulnerability'.

    Published: 14 Jul 2020
    5.4
    Medium

    CVE-2020-1456

    Last Modified: 28 Feb 2025

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1450, CVE-2020-1451.

    Published: 14 Jul 2020
    7.8
    High

    CVE-2020-1458

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files, aka 'Microsoft Office Remote Code Execution Vulnerability'.

    Published: 14 Jul 2020
    5.4
    Medium

    CVE-2020-1454

    Last Modified: 28 Feb 2025

    This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePoint server, aka 'Microsoft SharePoint Reflective XSS Vulnerability'.

    Published: 14 Jul 2020
    5.4
    Medium

    CVE-2020-1451

    Last Modified: 28 Feb 2025

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1450, CVE-2020-1456.

    Published: 14 Jul 2020
    7.8
    High

    CVE-2020-1449

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft Project software when the software fails to check the source markup of a file, aka 'Microsoft Project Remote Code Execution Vulnerability'.

    Published: 14 Jul 2020
    5.4
    Medium

    CVE-2020-1450

    Last Modified: 28 Feb 2025

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1451, CVE-2020-1456.

    Published: 14 Jul 2020
    8.8
    High

    CVE-2020-1447

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448.

    Published: 14 Jul 2020
    8.8
    High

    CVE-2020-1448

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1447.

    Published: 14 Jul 2020
    5.5
    Medium

    CVE-2020-1445

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1342.

    Published: 14 Jul 2020
    8.8
    High

    CVE-2020-1446

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.

    Published: 14 Jul 2020