CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2020-7457

    Last Modified: 21 Nov 2024

    In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_2292PKTOPTIONS socket option set handler contained a race condition allowing a malicious application to modify memory after being freed, possibly resulting in code execution.

    Published: 9 Jul 2020
    7.1
    High

    CVE-2020-5366

    Last Modified: 21 Nov 2024

    Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability by manipulating input parameters to gain unauthorized read access to the arbitrary files.

    Published: 9 Jul 2020
    —
    Unknown

    CVE-2019-10096

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 9 Jul 2020
    —
    Unknown

    CVE-2020-11992

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 9 Jul 2020
    7.5
    High

    CVE-2020-9376

    Last Modified: 21 Nov 2024

    D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 9 Jul 2020
    8.8
    High

    CVE-2020-9377

    Last Modified: 10 Nov 2025

    D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 9 Jul 2020
    8.1
    High

    CVE-2020-5604

    Last Modified: 21 Nov 2024

    Android App 'Mercari' (Japan version) prior to version 3.52.0 allows arbitrary method execution of a Java object by a remote attacker via a Man-In-The-Middle attack by using Java Reflection API of JavaScript code on WebView.

    Published: 9 Jul 2020
    5.5
    Medium

    CVE-2020-15945

    Last Modified: 19 Feb 2025

    Lua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) because it incorrectly expects that an oldpc value is always updated upon a return of the flow of control to a function.

    Published: 9 Jul 2020
    5.5
    Medium

    CVE-2020-27618

    Last Modified: 9 Jun 2025

    The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service, a different vulnerability from CVE-2016-10228.

    Published: 9 Jul 2020
    4.3
    Medium

    CVE-2020-12412

    Last Modified: 21 Nov 2024

    By navigating a tab using the history API, an attacker could cause the address bar to display the incorrect domain (with the https:// scheme, a blocked port number such as '1', and without a lock icon) while controlling the page contents. This vulnerability affects Firefox < 70.

    Published: 9 Jul 2020
    7.5
    High

    CVE-2020-14326

    Last Modified: 21 Nov 2024

    A vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, leading to slower requests with higher CPU time spent searching and adding the entry. This flaw allows an attacker to cause a denial of service.

    Published: 9 Jul 2020
    7.8
    High

    CVE-2020-5974

    Last Modified: 21 Nov 2024

    NVIDIA JetPack SDK, version 4.2 and 4.3, contains a vulnerability in its installation scripts in which permissions are incorrectly set on certain directories, which can lead to escalation of privileges.

    Published: 8 Jul 2020
    8.8
    High

    CVE-2020-15072

    Last Modified: 21 Nov 2024

    An issue was discovered in phpList through 3.5.4. An error-based SQL Injection vulnerability exists via the Import Administrators section.

    Published: 8 Jul 2020
    5.4
    Medium

    CVE-2020-15073

    Last Modified: 21 Nov 2024

    An issue was discovered in phpList through 3.5.4. An XSS vulnerability occurs within the Import Administrators section via upload of an edited text document. This also affects the Subscriber Lists section.

    Published: 8 Jul 2020
    7.5
    High

    CVE-2019-19415

    Last Modified: 21 Nov 2024

    The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leading to DoS condition. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-sip-en.

    Published: 8 Jul 2020
    7.5
    High

    CVE-2019-19416

    Last Modified: 21 Nov 2024

    The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leading to DoS condition. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-sip-en.

    Published: 8 Jul 2020
    7.5
    High

    CVE-2019-19417

    Last Modified: 21 Nov 2024

    The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leading to DoS condition. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-sip-en.

    Published: 8 Jul 2020
    8.1
    High

    CVE-2020-2034

    Last Modified: 21 Nov 2024

    An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacker to execute arbitrary OS commands with root privileges. An attacker requires some knowledge of the firewall to exploit this issue. This issue can not be exploited if GlobalProtect portal feature is not enabled. This issue impacts PAN-OS 9.1 versions earlier than PAN-OS 9.1.3; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; all versions of PAN-OS 8.0 and PAN-OS 7.1. Prisma Access services are not impacted by this vulnerability.

    Published: 8 Jul 2020
    4.9
    Medium

    CVE-2020-2031

    Last Modified: 21 Nov 2024

    An integer underflow vulnerability in the dnsproxyd component of the PAN-OS management interface allows authenticated administrators to issue a command from the command line interface that causes the component to stop responding. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode. This issue impacts: PAN-OS 9.1 versions earlier than PAN-OS 9.1.3. This issue does not impact PAN-OS 8.1, PAN-OS 9.0, or Prisma Access services.

    Published: 8 Jul 2020
    7.2
    High

    CVE-2020-2030

    Last Modified: 21 Nov 2024

    An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; and all versions of PAN-OS 7.1 and PAN-OS 8.0. This issue does not impact PAN-OS 9.0, PAN-OS 9.1, or Prisma Access services.

    Published: 8 Jul 2020
    4.8
    Medium

    CVE-2020-1982

    Last Modified: 21 Nov 2024

    Certain communication between PAN-OS and cloud-delivered services inadvertently use TLS 1.0, which is known to be a cryptographically weak protocol. These cloud services include Cortex Data Lake, the Customer Support Portal, and the Prisma Access infrastructure. Conditions required for exploitation of known TLS 1.0 weaknesses do not exist for the communication between PAN-OS and cloud-delivered services. We do not believe that any communication is impacted as a result of known attacks against TLS 1.0. This issue impacts: All versions of PAN-OS 8.0; PAN-OS 8.1 versions earlier than PAN-OS 8.1.14; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; PAN-OS 9.1 versions earlier than PAN-OS 9.1.3. PAN-OS 7.1 is not impacted by this issue.

    Published: 8 Jul 2020
    7.5
    High

    CVE-2020-5839

    Last Modified: 21 Nov 2024

    Symantec Endpoint Detection And Response, prior to 4.4, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.

    Published: 8 Jul 2020
    7.5
    High

    CVE-2020-6938

    Last Modified: 21 Nov 2024

    A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26, 2020, could allow access to sensitive information in log files.

    Published: 8 Jul 2020
    —
    Unknown

    CVE-2020-14476

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 8 Jul 2020
    8.8
    High

    CVE-2020-3973

    Last Modified: 21 Nov 2024

    The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged.

    Published: 8 Jul 2020
    6.1
    Medium

    CVE-2020-7140

    Last Modified: 21 Nov 2024

    A security vulnerability in HPE IceWall SSO Dfw and Dgfw (Domain Gateway Option) could be exploited remotely to cause a remote cross-site scripting (XSS). HPE has provided the following information to resolve this vulnerability in HPE IceWall SSO DFW and Dgfw: https://www.hpe.com/jp/icewall_patchaccess

    Published: 8 Jul 2020
    8.8
    High

    CVE-2020-5764

    Last Modified: 21 Nov 2024

    MX Player Android App versions prior to v1.24.5, are vulnerable to a directory traversal vulnerability when user is using the MX Transfer feature in "Receive" mode. An attacker can exploit this by connecting to the MX Transfer session as a "sender" and sending a MessageType of "FILE_LIST" with a "name" field containing directory traversal characters (../). This will result in the file being transferred to the victim's phone, but being saved outside of the intended "/sdcard/MXshare" directory. In some instances, an attacker can achieve remote code execution by writing ".odex" and ".vdex" files in the "oat" directory of the MX Player application.

    Published: 8 Jul 2020
    9.8
    Critical

    CVE-2020-11849

    Last Modified: 21 Nov 2024

    Elevation of privilege and/or unauthorized access vulnerability in Micro Focus Identity Manager. Affecting versions prior to 4.7.3 and 4.8.1 hot fix 1. The vulnerability could allow information exposure that can result in an elevation of privilege or an unauthorized access.

    Published: 8 Jul 2020
    9.8
    Critical

    CVE-2020-3931

    Last Modified: 21 Nov 2024

    Buffer overflow exists in Geovision Door Access Control device family, an unauthenticated remote attacker can execute arbitrary command.

    Published: 8 Jul 2020
    4.6
    Medium

    CVE-2020-15104

    Last Modified: 21 Nov 2024

    In Envoy before versions 1.12.6, 1.13.4, 1.14.4, and 1.15.0 when validating TLS certificates, Envoy would incorrectly allow a wildcard DNS Subject Alternative Name apply to multiple subdomains. For example, with a SAN of *.example.com, Envoy would incorrectly allow nested.subdomain.example.com, when it should only allow subdomain.example.com. This defect applies to both validating a client TLS certificate in mTLS, and validating a server TLS certificate for upstream connections. This vulnerability is only applicable to situations where an untrusted entity can obtain a signed wildcard TLS certificate for a domain of which you only intend to trust a subdomain of. For example, if you intend to trust api.mysubdomain.example.com, and an untrusted actor can obtain a signed TLS certificate for *.example.com or *.com. Configurations are vulnerable if they use verify_subject_alt_name in any Envoy version, or if they use match_subject_alt_names in version 1.14 or later. This issue has been fixed in Envoy versions 1.12.6, 1.13.4, 1.14.4, 1.15.0.

    Published: 8 Jul 2020
    6.5
    Medium

    CVE-2020-15648

    Last Modified: 21 Nov 2024

    Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2.

    Published: 8 Jul 2020
    7.5
    High

    CVE-2020-11994

    Last Modified: 21 Nov 2024

    Server-Side Template Injection and arbitrary file disclosure on Camel templating components

    Published: 8 Jul 2020
    5.4
    Medium

    CVE-2020-8558

    Last Modified: 21 Nov 2024

    The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's network namespace. Such a service is generally thought to be reachable only by other processes on the same host, but due to this defeect, could be reachable by other hosts on the same LAN as the node, or by containers running on the same node as the service.

    Published: 8 Jul 2020
    6.5
    Medium

    CVE-2020-15600

    Last Modified: 21 Nov 2024

    An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.

    Published: 7 Jul 2020
    6.1
    Medium

    CVE-2020-15599

    Last Modified: 21 Nov 2024

    Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.

    Published: 7 Jul 2020
    5
    Medium

    CVE-2020-8916

    Last Modified: 21 Nov 2024

    A memory leak in Openthread's wpantund versions up to commit 0e5d1601febb869f583e944785e5685c6c747be7, when used in an environment where wpanctl is directly interfacing with the control driver (eg: debug environments) can allow an attacker to crash the service (DoS). We recommend updating, or to restrict access in your debug environments.

    Published: 7 Jul 2020
    7.5
    High

    CVE-2020-15008

    Last Modified: 21 Nov 2024

    A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement and utilizes the user supplied table name with little validation, the table name can be modified to allow arbitrary update commands to be run. Usage of other SQL injection techniques such as timing attacks, it is possible to perform full data extraction as well. Patched in 2020.7 and in a hotfix for 2019.12.

    Published: 7 Jul 2020
    7.2
    High

    CVE-2020-12736

    Last Modified: 21 Nov 2024

    Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution. When an administrator creates a local (non-SSO) user via a Code42-generated email, the administrator has the option to modify content for the email invitation. If the administrator entered template language code in the subject line, that code could be interpreted by the email generation services, potentially resulting in server-side code injection.

    Published: 7 Jul 2020
    9.8
    Critical

    CVE-2020-8521

    Last Modified: 21 Nov 2024

    SQL injection with start and length parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql

    Published: 7 Jul 2020
    9.8
    Critical

    CVE-2020-8519

    Last Modified: 21 Nov 2024

    SQL injection with the search parameter in Records.php for phpzag live add edit delete data tables records with ajax php mysql

    Published: 7 Jul 2020
    9.8
    Critical

    CVE-2020-8520

    Last Modified: 21 Nov 2024

    SQL injection in order and column parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql

    Published: 7 Jul 2020
    9.8
    Critical

    CVE-2020-12821

    Last Modified: 21 Nov 2024

    Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.

    Published: 7 Jul 2020
    9.8
    Critical

    CVE-2019-20896

    Last Modified: 21 Nov 2024

    WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter.

    Published: 7 Jul 2020
    9.8
    Critical

    CVE-2020-15350

    Last Modified: 21 Nov 2024

    RIOT 2020.04 has a buffer overflow in the base64 decoder. The decoding function base64_decode() uses an output buffer estimation function to compute the required buffer capacity and validate against the provided buffer size. The base64_estimate_decode_size() function calculates the expected decoded size with an arithmetic round-off error and does not take into account possible padding bytes. Due to this underestimation, it may be possible to craft base64 input that causes a buffer overflow.

    Published: 7 Jul 2020
    6.1
    Medium

    CVE-2019-19935

    Last Modified: 21 Nov 2024

    Froala Editor before 3.2.3 allows XSS.

    Published: 7 Jul 2020
    6.1
    Medium

    CVE-2020-11882

    Last Modified: 21 Nov 2024

    The O2 Business application 1.2.0 for Android exposes the canvasm.myo2.SplashActivity activity to other applications. The purpose of this activity is to handle deeplinks that can be delivered either via links or by directly calling the activity. However, the deeplink format is not properly validated. This can be abused by an attacker to redirect a user to any page and deliver any content to the user.

    Published: 7 Jul 2020
    5.4
    Medium

    CVE-2020-15028

    Last Modified: 21 Nov 2024

    NeDi 1.9C is vulnerable to a cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Map.php xo parameter.

    Published: 7 Jul 2020
    5.4
    Medium

    CVE-2020-15029

    Last Modified: 21 Nov 2024

    NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Assets-Management.php sn parameter.

    Published: 7 Jul 2020
    5.4
    Medium

    CVE-2020-15030

    Last Modified: 21 Nov 2024

    NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Routes.php rtr parameter.

    Published: 7 Jul 2020
    5.4
    Medium

    CVE-2020-15031

    Last Modified: 21 Nov 2024

    NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Assets-Management.php chg parameter.

    Published: 7 Jul 2020