CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2020-6521

    Last Modified: 21 Nov 2024

    Side-channel information leakage in autofill in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 14 Jul 2020
    8.8
    High

    CVE-2020-6523

    Last Modified: 21 Nov 2024

    Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 14 Jul 2020
    8.8
    High

    CVE-2020-6525

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 14 Jul 2020
    4.3
    Medium

    CVE-2020-6527

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.

    Published: 14 Jul 2020
    4.3
    Medium

    CVE-2020-6529

    Last Modified: 21 Nov 2024

    Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page.

    Published: 14 Jul 2020
    4.3
    Medium

    CVE-2020-6531

    Last Modified: 21 Nov 2024

    Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 14 Jul 2020
    7.5
    High

    CVE-2020-15050

    Last Modified: 21 Nov 2024

    An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary files from the server via Directory Traversal.

    Published: 13 Jul 2020
    9.8
    Critical

    CVE-2020-10987

    Last Modified: 7 Nov 2025

    The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.

    Published: 13 Jul 2020
    6.1
    Medium

    CVE-2020-10989

    Last Modified: 21 Nov 2024

    An XSS issue in the /goform/WifiBasicSet endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute malicious payloads via the WifiName POST parameter.

    Published: 13 Jul 2020
    9.8
    Critical

    CVE-2020-10988

    Last Modified: 21 Nov 2024

    A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated remote attackers to start a telnetd service on the device.

    Published: 13 Jul 2020
    6.5
    Medium

    CVE-2020-10986

    Last Modified: 21 Nov 2024

    A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to reboot the device and cause denial of service via a payload hosted by an attacker-controlled web page.

    Published: 13 Jul 2020
    7.5
    High

    CVE-2020-5766

    Last Modified: 21 Nov 2024

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3 and 1.0.4 allows a remote, unauthenticated attacker to determine the value of database fields.

    Published: 13 Jul 2020
    9
    Critical

    CVE-2020-11749

    Last Modified: 21 Nov 2024

    Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (XSS), which can run arbitrary code to allow Remote Code Execution as root or apache2.

    Published: 13 Jul 2020
    7.8
    High

    CVE-2019-4591

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6.0 and 7.6.1 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 167451.

    Published: 13 Jul 2020
    7.5
    High

    CVE-2020-15689

    Last Modified: 21 Nov 2024

    Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This may result in a NULL pointer dereference and cause a denial of service.

    Published: 13 Jul 2020
    6.1
    Medium

    CVE-2019-20901

    Last Modified: 21 Nov 2024

    The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect in the os_destination parameter.

    Published: 13 Jul 2020
    4.3
    Medium

    CVE-2020-14174

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, from version 8.6.0 before 8.9.2, and from version 8.10.0 before 8.10.1.

    Published: 13 Jul 2020
    4.8
    Medium

    CVE-2019-20900

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the Add Field module. The affected versions are before version 8.7.0.

    Published: 13 Jul 2020
    5.3
    Medium

    CVE-2019-20899

    Last Modified: 21 Nov 2024

    The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1.

    Published: 13 Jul 2020
    7.5
    High

    CVE-2019-20898

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the Global permissions screen. The affected versions are before version 8.8.0.

    Published: 13 Jul 2020
    6.5
    Medium

    CVE-2019-20897

    Last Modified: 21 Nov 2024

    The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a crafted PNG file. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1.

    Published: 13 Jul 2020
    5.5
    Medium

    CVE-2020-23903

    Last Modified: 21 Nov 2024

    A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.

    Published: 13 Jul 2020
    6.5
    Medium

    CVE-2020-14336

    Last Modified: 21 Nov 2024

    A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an attacker to cause a denial of service attack on an OpenShift Container Platform cluster if they can deploy pods. The highest threat from this vulnerability is to system availability.

    Published: 13 Jul 2020
    7.5
    High

    CVE-2020-24372

    Last Modified: 3 Nov 2025

    LuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c.

    Published: 13 Jul 2020
    7.5
    High

    CVE-2020-15890

    Last Modified: 3 Nov 2025

    LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.

    Published: 11 Jul 2020
    5.4
    Medium

    CVE-2020-15105

    Last Modified: 21 Nov 2024

    Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encoded). The password is stored in the session when the user submits their username and password, and is removed once they complete authentication by entering a two-factor authentication code. This means that the password is stored in clear text in the session for an arbitrary amount of time, and potentially forever if the user begins the login process by entering their username and password and then leaves before entering their two-factor authentication code. The severity of this issue depends on which type of session storage you have configured: in the worst case, if you're using Django's default database session storage, then users' passwords are stored in clear text in your database. In the best case, if you're using Django's signed cookie session, then users' passwords are only stored in clear text within their browser's cookie store. In the common case of using Django's cache session store, the users' passwords are stored in clear text in whatever cache storage you have configured (typically Memcached or Redis). This has been fixed in 1.12. After upgrading, users should be sure to delete any clear text passwords that have been stored. For example, if you're using the database session backend, you'll likely want to delete any session record from the database and purge that data from any database backups or replicas. In addition, affected organizations who have suffered a database breach while using an affected version should inform their users that their clear text passwords have been compromised. All organizations should encourage users whose passwords were insecurely stored to change these passwords on any sites where they were used. As a workaround, wwitching Django's session storage to use signed cookies instead of the database or cache lessens the impact of this issue, but should not be done without a thorough understanding of the security tradeoffs of using signed cookies rather than a server-side session storage. There is no way to fully mitigate the issue without upgrading.

    Published: 10 Jul 2020
    6.8
    Medium

    CVE-2020-4042

    Last Modified: 21 Nov 2024

    Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated connection and connects to the client itself. The malicious client can replay the Bareos director's cram-md5 challenge to the director itself leading to the director responding to the replayed challenge. The response obtained is then a valid reply to the directors original challenge. This is fixed in version 19.2.8.

    Published: 10 Jul 2020
    6
    Medium

    CVE-2020-11061

    Last Modified: 21 Nov 2024

    In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mitigates the problem. This issue is also patched in Bareos versions 19.2.8, 18.2.9 and 17.2.10.

    Published: 10 Jul 2020
    5.3
    Medium

    CVE-2020-11081

    Last Modified: 21 Nov 2024

    osquery before version 4.4.0 enables a privilege escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables local escalation. This is fixed in version 4.4.0.

    Published: 10 Jul 2020
    7.2
    High

    CVE-2020-6114

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 10 Jul 2020
    9.8
    Critical

    CVE-2020-15504

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) and the v17.5 MR13 release. All other versions >= 17.0 have received a hotfix.

    Published: 10 Jul 2020
    4.3
    Medium

    CVE-2020-8181

    Last Modified: 21 Nov 2024

    A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars.

    Published: 10 Jul 2020
    7.8
    High

    CVE-2020-8199

    Last Modified: 21 Nov 2024

    Improper access control in Citrix ADC Gateway Linux client versions before 1.0.0.137 results in local privilege escalation to root.

    Published: 10 Jul 2020
    8.8
    High

    CVE-2020-8197

    Last Modified: 21 Nov 2024

    Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows a low privileged user with management access to execute arbitrary commands.

    Published: 10 Jul 2020
    4.3
    Medium

    CVE-2020-8196

    Last Modified: 30 Oct 2025

    Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.

    Published: 10 Jul 2020
    6.5
    Medium

    CVE-2020-8195

    Last Modified: 30 Oct 2025

    Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.

    Published: 10 Jul 2020
    6.1
    Medium

    CVE-2020-8198

    Last Modified: 21 Nov 2024

    Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in Stored Cross-Site Scripting (XSS).

    Published: 10 Jul 2020
    6.5
    Medium

    CVE-2020-8194

    Last Modified: 21 Nov 2024

    Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the modification of a file download.

    Published: 10 Jul 2020
    6.5
    Medium

    CVE-2020-8193

    Last Modified: 30 Oct 2025

    Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.

    Published: 10 Jul 2020
    6.1
    Medium

    CVE-2020-8191

    Last Modified: 21 Nov 2024

    Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).

    Published: 10 Jul 2020
    9.8
    Critical

    CVE-2020-8186

    Last Modified: 21 Nov 2024

    A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `certificateFor` function.

    Published: 10 Jul 2020
    7.5
    High

    CVE-2020-8187

    Last Modified: 21 Nov 2024

    Improper input validation in Citrix ADC and Citrix Gateway versions before 11.1-63.9 and 12.0-62.10 allows unauthenticated users to perform a denial of service attack.

    Published: 10 Jul 2020
    7.5
    High

    CVE-2020-8190

    Last Modified: 21 Nov 2024

    Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows privilege escalation.

    Published: 10 Jul 2020
    —
    Unknown

    CVE-2020-13983

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-14159. Reason: This candidate is a reservation duplicate of CVE-2020-14159. Notes: All CVE users should reference CVE-2020-14159 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 Jul 2020
    —
    Unknown

    CVE-2013-1703

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2013. Notes: none

    Published: 10 Jul 2020
    —
    Unknown

    CVE-2013-0802

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2013. Notes: none

    Published: 10 Jul 2020
    —
    Unknown

    CVE-2012-6492

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2012. Notes: none

    Published: 10 Jul 2020
    —
    Unknown

    CVE-2012-6491

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2012. Notes: none

    Published: 10 Jul 2020
    —
    Unknown

    CVE-2012-6490

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2012. Notes: none

    Published: 10 Jul 2020
    —
    Unknown

    CVE-2012-6489

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2012. Notes: none

    Published: 10 Jul 2020