CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2020-7281

    Last Modified: 21 Nov 2024

    Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.

    Published: 3 Jul 2020
    7.5
    High

    CVE-2020-7282

    Last Modified: 21 Nov 2024

    Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.

    Published: 3 Jul 2020
    8.8
    High

    CVE-2020-15518

    Last Modified: 21 Nov 2024

    VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged users to achieve total control over filesystem I/O requests.

    Published: 3 Jul 2020
    5.4
    Medium

    CVE-2020-14173

    Last Modified: 21 Nov 2024

    The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1.

    Published: 3 Jul 2020
    9.8
    Critical

    CVE-2020-14172

    Last Modified: 21 Nov 2024

    This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. The way in which velocity templates were used in Atlassian Jira Server and Data Center in affected versions allowed remote attackers to achieve remote code execution via insecure deserialization, if they were able to exploit a server side template injection vulnerability. The affected versions are before version 7.13.0, from version 8.0.0 before 8.5.0, and from version 8.6.0 before version 8.8.1.

    Published: 3 Jul 2020
    7.8
    High

    CVE-2019-20419

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitrary code via a DLL hijacking vulnerability in Tomcat. The affected versions are before version 8.5.5, and from version 8.6.0 before 8.7.2.

    Published: 3 Jul 2020
    6.5
    Medium

    CVE-2019-20418

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the instance via an Application Denial of Service vulnerability in the /rendering/wiki endpoint. The affected versions are before version 8.8.0.

    Published: 3 Jul 2020
    7.4
    High

    CVE-2020-7692

    Last Modified: 21 Nov 2024

    PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorization request is the one that will be authorized. An attacker is able to obtain the authorization code using a malicious app on the client-side and use it to gain authorization to the protected resource. This affects the package com.google.oauth-client:google-oauth-client before 1.31.0.

    Published: 3 Jul 2020
    5.3
    Medium

    CVE-2020-7693

    Last Modified: 21 Nov 2024

    Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.

    Published: 3 Jul 2020
    6.1
    Medium

    CVE-2020-8176

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the `shop` parameter on the `/shopify/auth/enable_cookies` endpoint.

    Published: 2 Jul 2020
    4.1
    Medium

    CVE-2020-8179

    Last Modified: 21 Nov 2024

    Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.

    Published: 2 Jul 2020
    8.8
    High

    CVE-2020-8188

    Last Modified: 21 Nov 2024

    We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and UniFi Dream Machine Pro/UNVR respectively that fixes vulnerabilities found on Protect firmware v1.13.2, v1.14.9 and prior according to the description below:View only users can run certain custom commands which allows them to assign themselves unauthorized roles and escalate their privileges.

    Published: 2 Jul 2020
    8.9
    High

    CVE-2020-4074

    Last Modified: 21 Nov 2024

    In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and execute admin commands. The problem is fixed in 1.7.6.6.

    Published: 2 Jul 2020
    6.5
    Medium

    CVE-2020-15091

    Last Modified: 21 Nov 2024

    TenderMint from version 0.33.0 and before version 0.33.6 allows block proposers to include signatures for the wrong block. This may happen naturally if you start a network, have it run for some time and restart it (**without changing chainID**). A malicious block proposer (even with a minimal amount of stake) can use this vulnerability to completely halt the network. This issue is fixed in Tendermint 0.33.6 which checks all the signatures are for the block with 2/3+ majority before creating a commit.

    Published: 2 Jul 2020
    3.7
    Low

    CVE-2020-4061

    Last Modified: 21 Nov 2024

    In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froala richeditor could result in a successful self-XSS attack. This has been fixed in 1.0.467.

    Published: 2 Jul 2020
    7.1
    High

    CVE-2020-15082

    Last Modified: 21 Nov 2024

    In PrestaShop from version 1.6.0.1 and before version 1.7.6.6, the dashboard allows rewriting all configuration variables. The problem is fixed in 1.7.6.6

    Published: 2 Jul 2020
    4.7
    Medium

    CVE-2020-15083

    Last Modified: 21 Nov 2024

    In PrestaShop from version 1.7.0.0 and before version 1.7.6.6, if a target sends a corrupted file, it leads to a reflected XSS. The problem is fixed in 1.7.6.6

    Published: 2 Jul 2020
    5.4
    Medium

    CVE-2020-11074

    Last Modified: 21 Nov 2024

    In PrestaShop from version 1.5.3.0 and before version 1.7.6.6, there is a stored XSS when using the name of a quick access item. The problem is fixed in 1.7.6.6.

    Published: 2 Jul 2020
    6.4
    Medium

    CVE-2020-15079

    Last Modified: 21 Nov 2024

    In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module Manager and Module Positions. The problem is fixed in version 1.7.6.6

    Published: 2 Jul 2020
    5.3
    Medium

    CVE-2020-15080

    Last Modified: 21 Nov 2024

    In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and others should not be accessible. The problem is fixed in version 1.7.6.6 A possible workaround is to make sure `composer.json` and `docker-compose.yml` are not accessible on your server.

    Published: 2 Jul 2020
    5.3
    Medium

    CVE-2020-15081

    Last Modified: 21 Nov 2024

    In PrestaShop from version 1.5.0.0 and before 1.7.6.6, there is information exposure in the upload directory. The problem is fixed in version 1.7.6.6. A possible workaround is to add an empty index.php file in the upload directory.

    Published: 2 Jul 2020
    4.3
    Medium

    CVE-2020-14348

    Last Modified: 21 Nov 2024

    It was found in AMQ Online before 1.5.2 that injecting an invalid field to a user's AddressSpace configuration of the user namespace puts AMQ Online in an inconsistent state, where the AMQ Online components do not operate properly, such as the failure of provisioning and the failure of creating addresses, though this does not impact upon already existing messaging clients or brokers.

    Published: 2 Jul 2020
    7.5
    High

    CVE-2019-20894

    Last Modified: 21 Nov 2024

    Traefik 2.x, in certain configurations, allows HTTPS sessions to proceed without mutual TLS verification in a situation where ERR_BAD_SSL_CLIENT_AUTH_CERT should have occurred.

    Published: 2 Jul 2020
    9.8
    Critical

    CVE-2020-14092

    Last Modified: 21 Nov 2024

    The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.

    Published: 2 Jul 2020
    6.1
    Medium

    CVE-2020-13653

    Last Modified: 21 Nov 2024

    An XSS vulnerability exists in the Webmail component of Zimbra Collaboration Suite before 8.8.15 Patch 11. It allows an attacker to inject executable JavaScript into the account name of a user's profile. The injected code can be reflected and executed when changing an e-mail signature.

    Published: 2 Jul 2020
    5.4
    Medium

    CVE-2020-2219

    Last Modified: 21 Nov 2024

    Jenkins Link Column Plugin 1.0 and earlier does not filter URLs of links created by users with View/Configure permission, resulting in a stored cross-site scripting vulnerability.

    Published: 2 Jul 2020
    4.3
    Medium

    CVE-2020-2216

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified username and password.

    Published: 2 Jul 2020
    3.3
    Low

    CVE-2020-2218

    Last Modified: 21 Nov 2024

    Jenkins HP ALM Quality Center Plugin 1.6 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.

    Published: 2 Jul 2020
    6.1
    Medium

    CVE-2020-2217

    Last Modified: 21 Nov 2024

    Jenkins Compatibility Action Storage Plugin 1.0 and earlier does not escape the content coming from the MongoDB in the testConnection form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.

    Published: 2 Jul 2020
    5.4
    Medium

    CVE-2020-2214

    Last Modified: 21 Nov 2024

    Jenkins ZAP Pipeline Plugin 1.9 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.

    Published: 2 Jul 2020
    4.3
    Medium

    CVE-2020-2215

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified username and password.

    Published: 2 Jul 2020
    4.3
    Medium

    CVE-2020-2212

    Last Modified: 21 Nov 2024

    Jenkins GitHub Coverage Reporter Plugin 1.8 and earlier stores secrets unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system or read permissions on the system configuration.

    Published: 2 Jul 2020
    4.3
    Medium

    CVE-2020-2213

    Last Modified: 21 Nov 2024

    Jenkins White Source Plugin 19.1.1 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission (config.xml), or access to the master file system.

    Published: 2 Jul 2020
    8.8
    High

    CVE-2020-2211

    Last Modified: 21 Nov 2024

    Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

    Published: 2 Jul 2020
    4.3
    Medium

    CVE-2020-2209

    Last Modified: 21 Nov 2024

    Jenkins TestComplete support Plugin 2.4.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.

    Published: 2 Jul 2020
    4.3
    Medium

    CVE-2020-2210

    Last Modified: 21 Nov 2024

    Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.

    Published: 2 Jul 2020
    6.1
    Medium

    CVE-2020-2207

    Last Modified: 21 Nov 2024

    Jenkins VncViewer Plugin 1.7 and earlier does not escape a parameter value in the checkVncServ form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.

    Published: 2 Jul 2020
    4.3
    Medium

    CVE-2020-2208

    Last Modified: 21 Nov 2024

    Jenkins Slack Upload Plugin 1.7 and earlier stores a secret unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.

    Published: 2 Jul 2020
    5.4
    Medium

    CVE-2020-2204

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to the globally configured Fortify on Demand endpoint using attacker-specified credentials IDs.

    Published: 2 Jul 2020
    4.8
    Medium

    CVE-2020-2205

    Last Modified: 21 Nov 2024

    Jenkins VncRecorder Plugin 1.25 and earlier does not escape a tool path in the `checkVncServ` form validation endpoint, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by Jenkins administrators.

    Published: 2 Jul 2020
    6.1
    Medium

    CVE-2020-2206

    Last Modified: 21 Nov 2024

    Jenkins VncRecorder Plugin 1.25 and earlier does not escape a parameter value in the checkVncServ form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.

    Published: 2 Jul 2020
    4.3
    Medium

    CVE-2020-2202

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Fortify on Demand Plugin 6.0.0 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

    Published: 2 Jul 2020
    4.3
    Medium

    CVE-2020-2203

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers to connect to the globally configured Fortify on Demand endpoint using attacker-specified credentials IDs.

    Published: 2 Jul 2020
    5.4
    Medium

    CVE-2020-2201

    Last Modified: 21 Nov 2024

    Jenkins Sonargraph Integration Plugin 3.0.0 and earlier does not escape the file path for the Log file field form validation, resulting in a stored cross-site scripting vulnerability.

    Published: 2 Jul 2020
    8.1
    High

    CVE-2020-12119

    Last Modified: 21 Nov 2024

    Ledger Live before 2.7.0 does not handle Bitcoin's Replace-By-Fee (RBF). It increases the user's balance with the value of an unconfirmed transaction as soon as it is received (before the transaction is confirmed) and does not decrease the balance when it is canceled. As a result, users are exposed to basic double spending attacks, amplified double spending attacks, and DoS attacks without user consent.

    Published: 2 Jul 2020
    6.1
    Medium

    CVE-2020-3282

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.

    Published: 2 Jul 2020
    7.8
    High

    CVE-2020-7820

    Last Modified: 21 Nov 2024

    Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by setting the arguments to the vulnerable API. This can be leveraged for code execution by rebooting the victim’s PC

    Published: 2 Jul 2020
    7.8
    High

    CVE-2020-7821

    Last Modified: 21 Nov 2024

    Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by modifying the value of registry path. This can be leveraged for code execution by rebooting the victim’s PC

    Published: 2 Jul 2020
    6.7
    Medium

    CVE-2020-9498

    Last Modified: 21 Nov 2024

    Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed with the privileges of therunning guacd process.

    Published: 2 Jul 2020
    4.4
    Medium

    CVE-2020-9497

    Last Modified: 21 Nov 2024

    Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in disclosure of information within the memory ofthe guacd process handling the connection.

    Published: 2 Jul 2020