CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2020-5909

    Last Modified: 21 Nov 2024

    In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.

    Published: 2 Jul 2020
    7.5
    High

    CVE-2020-5910

    Last Modified: 21 Nov 2024

    In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.

    Published: 2 Jul 2020
    7.3
    High

    CVE-2020-5911

    Last Modified: 21 Nov 2024

    In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system.

    Published: 2 Jul 2020
    7.5
    High

    CVE-2020-15502

    Last Modified: 21 Nov 2024

    The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests to servers in the duckduckgo.com domain, which might make visit data available temporarily at a Potentially Unwanted Endpoint. NOTE: the vendor has stated "the favicon service adheres to our strict privacy policy.

    Published: 2 Jul 2020
    7.5
    High

    CVE-2020-3402

    Last Modified: 21 Nov 2024

    A vulnerability in the Java Remote Method Invocation (RMI) interface of Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability exists because certain RMI listeners are not properly authenticated. An attacker could exploit this vulnerability by sending a crafted request to the affected listener. A successful exploit could allow the attacker to access sensitive information on an affected device.

    Published: 2 Jul 2020
    6.5
    Medium

    CVE-2020-3391

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to insecure storage of certain unencrypted credentials on an affected device. An attacker could exploit this vulnerability by viewing the network device configuration and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices.

    Published: 2 Jul 2020
    4.8
    Medium

    CVE-2020-3340

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input that is processed by the web-based management interface. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information. To exploit these vulnerabilities, an attacker would need valid administrative credentials.

    Published: 2 Jul 2020
    9.8
    Critical

    CVE-2020-3297

    Last Modified: 21 Nov 2024

    A vulnerability in session management for the web-based interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to defeat authentication protections and gain unauthorized access to the management interface. The attacker could obtain the privileges of the highjacked session account, which could include administrator privileges on the device. The vulnerability is due to the use of weak entropy generation for session identifier values. An attacker could exploit this vulnerability to determine a current session identifier through brute force and reuse that session identifier to take over an ongoing session. In this way, an attacker could take actions within the management interface with privileges up to the level of the administrative user.

    Published: 2 Jul 2020
    6.1
    Medium

    CVE-2020-10748

    Last Modified: 21 Nov 2024

    A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks.

    Published: 2 Jul 2020
    6.5
    Medium

    CVE-2020-10760

    Last Modified: 21 Nov 2024

    A use-after-free flaw was found in all samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in a AC DC configuration. A Samba LDAP user could use this flaw to crash samba.

    Published: 2 Jul 2020
    4.9
    Medium

    CVE-2020-1694

    Last Modified: 21 Nov 2024

    A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.

    Published: 2 Jul 2020
    7.5
    High

    CVE-2020-10745

    Last Modified: 21 Nov 2024

    A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows a remote attacker could to cause the Samba server to consume excessive CPU use, resulting in a denial of service. This highest threat from this vulnerability is to system availability.

    Published: 2 Jul 2020
    6.5
    Medium

    CVE-2020-10730

    Last Modified: 21 Nov 2024

    A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17, before 4.11.11 and before 4.12.4. Although some versions of Samba shipped with Red Hat Enterprise Linux do not support Samba in AD mode, the affected code is shipped with the libldb package. This flaw allows an authenticated user to possibly trigger a use-after-free or NULL pointer dereference. The highest threat from this vulnerability is to system availability.

    Published: 2 Jul 2020
    7.5
    High

    CVE-2020-14303

    Last Modified: 21 Nov 2024

    A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash.

    Published: 2 Jul 2020
    6.1
    Medium

    CVE-2020-15500

    Last Modified: 21 Nov 2024

    An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflected XSS.

    Published: 1 Jul 2020
    9.8
    Critical

    CVE-2020-15489

    Last Modified: 21 Nov 2024

    An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulnerabilities exist in CGI scripts, leading to remote code execution with root privileges.

    Published: 1 Jul 2020
    9.8
    Critical

    CVE-2020-15490

    Last Modified: 21 Nov 2024

    An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple buffer overflow vulnerabilities exist in CGI scripts, leading to remote code execution with root privileges. (The set of affected scripts is similar to CVE-2020-12266.)

    Published: 1 Jul 2020
    8.8
    High

    CVE-2019-15312

    Last Modified: 21 Nov 2024

    An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is a Zolo Halo DNS rebinding attack. The device was found to be vulnerable to DNS rebinding. Combined with one of the many /httpapi.asp endpoint command-execution security issues, the DNS rebinding attack could allow an attacker to compromise the victim device from the Internet.

    Published: 1 Jul 2020
    9.8
    Critical

    CVE-2019-15311

    Last Modified: 21 Nov 2024

    An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is Zolo Halo LAN remote code execution. The Zolo Halo Bluetooth speaker had a GoAhead web server listening on the port 80. The /httpapi.asp endpoint of the GoAhead web server was also vulnerable to multiple command execution vulnerabilities.

    Published: 1 Jul 2020
    9.8
    Critical

    CVE-2019-15310

    Last Modified: 21 Nov 2024

    An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the firmware and obtain full control over Linkplay's AWS estate, including S3 buckets containing device firmware. When combined with an OS command injection vulnerability within the XML Parsing logic of the firmware update process, an attacker would be able to gain code execution on any device that attempted to update. Note that by default all devices tested had automatic updates enabled.

    Published: 1 Jul 2020
    5.3
    Medium

    CVE-2020-14196

    Last Modified: 21 Nov 2024

    In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enforced.

    Published: 1 Jul 2020
    9.8
    Critical

    CVE-2020-13619

    Last Modified: 21 Nov 2024

    php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution.

    Published: 1 Jul 2020
    8.4
    High

    CVE-2020-7688

    Last Modified: 21 Nov 2024

    The issue occurs because tagName user input is formatted inside the exec function is executed without any checks.

    Published: 1 Jul 2020
    9.8
    Critical

    CVE-2020-14057

    Last Modified: 21 Nov 2024

    Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments.

    Published: 1 Jul 2020
    6.1
    Medium

    CVE-2020-14055

    Last Modified: 21 Nov 2024

    Monsta FTP 2.10.1 or below is prone to a stored cross-site scripting vulnerability in the language setting due to insufficient output encoding.

    Published: 1 Jul 2020
    9.8
    Critical

    CVE-2020-14056

    Last Modified: 21 Nov 2024

    Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arbitrary local files and interact with arbitrary third-party services.

    Published: 1 Jul 2020
    9.8
    Critical

    CVE-2020-2500

    Last Modified: 21 Nov 2024

    This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to mitigate the vulnerability, and already fixed the issue in Helpdesk 3.0.1 and later versions.

    Published: 1 Jul 2020
    7.8
    High

    CVE-2020-12498

    Last Modified: 21 Nov 2024

    mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerable to out-of-bounds read remote code execution. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation.

    Published: 1 Jul 2020
    7.8
    High

    CVE-2020-12497

    Last Modified: 21 Nov 2024

    PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-based overflow. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation.

    Published: 1 Jul 2020
    7.8
    High

    CVE-2020-6089

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the ANI file format parser of Leadtools 20. A specially crafted ANI file can cause a buffer overflow resulting in remote code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 1 Jul 2020
    7.2
    High

    CVE-2020-5907

    Last Modified: 21 Nov 2024

    In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, an authorized user provided with access only to the TMOS Shell (tmsh) may be able to conduct arbitrary file read/writes via the built-in sftp functionality.

    Published: 1 Jul 2020
    6.1
    Medium

    CVE-2020-5903

    Last Modified: 21 Nov 2024

    In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.

    Published: 1 Jul 2020
    4.3
    Medium

    CVE-2020-5905

    Last Modified: 21 Nov 2024

    In version 11.6.1-11.6.5.2 of the BIG-IP system Configuration utility Network > WCCP page, the system does not sanitize all user-provided data before display.

    Published: 1 Jul 2020
    8.8
    High

    CVE-2020-5904

    Last Modified: 21 Nov 2024

    In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSRF) vulnerability in the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, exists in an undisclosed page.

    Published: 1 Jul 2020
    5.5
    Medium

    CVE-2020-5908

    Last Modified: 21 Nov 2024

    In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in the local log files.

    Published: 1 Jul 2020
    8.1
    High

    CVE-2020-5906

    Last Modified: 21 Nov 2024

    In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the access controls for the scp.blacklist files. This allows Admin and Resource Admin users with Secure Copy (SCP) protocol access to read and overwrite blacklisted files via SCP.

    Published: 1 Jul 2020
    7.5
    High

    CVE-2020-4420

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated attacker to cause a denial of service due a hang in the execution of a terminate command. IBM X-Force ID: 180076.

    Published: 1 Jul 2020
    4.4
    Medium

    CVE-2020-4414

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local attacker to perform unauthorized actions on the system, caused by improper usage of shared memory. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information or cause a denial of service. IBM X-Force ID: 179989.

    Published: 1 Jul 2020
    4.7
    Medium

    CVE-2020-4387

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to obtain sensitive information using a race condition of a symbolic link. IBM X-Force ID: 179269.

    Published: 1 Jul 2020
    4.7
    Medium

    CVE-2020-4386

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to obtain sensitive information using a race condition of a symbolic link. IBM X-Force ID: 179268.

    Published: 1 Jul 2020
    6.5
    Medium

    CVE-2020-4376

    Last Modified: 21 Nov 2024

    IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0.4 and 8.1.0 could allow an attacker to cause a denial of service caused by an error within the pubsub logic. IBM X-Force ID: 179081.

    Published: 1 Jul 2020
    7.8
    High

    CVE-2020-4363

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 178960.

    Published: 1 Jul 2020
    5.3
    Medium

    CVE-2020-4355

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service, caused by improper handling of Secure Sockets Layer (SSL) renegotiation requests. By sending specially-crafted requests, a remote attacker could exploit this vulnerability to increase the resource usage on the system. IBM X-Force ID: 178507.

    Published: 1 Jul 2020
    2.7
    Low

    CVE-2019-4706

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager Virtual Appliance 7.0.2 writes information to log files which can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information. IBM X-Force ID: 172016.

    Published: 1 Jul 2020
    2.7
    Low

    CVE-2019-4705

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager Virtual Appliance 7.0.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 172015.

    Published: 1 Jul 2020
    4.3
    Medium

    CVE-2019-4704

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager Virtual Appliance 7.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 172014.

    Published: 1 Jul 2020
    7.8
    High

    CVE-2019-4676

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager Virtual Appliance 7.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171512.

    Published: 1 Jul 2020
    7.5
    High

    CVE-2020-13383

    Last Modified: 21 Nov 2024

    openSIS through 7.4 allows Directory Traversal.

    Published: 1 Jul 2020
    9.1
    Critical

    CVE-2020-13382

    Last Modified: 21 Nov 2024

    openSIS through 7.4 has Incorrect Access Control.

    Published: 1 Jul 2020
    9.8
    Critical

    CVE-2020-13381

    Last Modified: 21 Nov 2024

    openSIS through 7.4 allows SQL Injection.

    Published: 1 Jul 2020