CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-13380

    Last Modified: 21 Nov 2024

    openSIS before 7.4 allows SQL Injection.

    Published: 1 Jul 2020
    9.6
    Critical

    CVE-2020-5901

    Last Modified: 21 Nov 2024

    In NGINX Controller 3.3.0-3.4.0, undisclosed API endpoints may allow for a reflected Cross Site Scripting (XSS) attack. If the victim user is logged in as admin this could result in a complete compromise of the system.

    Published: 1 Jul 2020
    7.8
    High

    CVE-2020-5899

    Last Modified: 21 Nov 2024

    In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read access to the database, to request a password reset using the email address of another registered user then retrieve the recovery code.

    Published: 1 Jul 2020
    8.8
    High

    CVE-2020-5900

    Last Modified: 21 Nov 2024

    In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for the NGINX Controller user interface.

    Published: 1 Jul 2020
    5.9
    Medium

    CVE-2020-7689

    Last Modified: 21 Nov 2024

    Data is truncated wrong when its length is greater than 255 bytes.

    Published: 1 Jul 2020
    5.9
    Medium

    CVE-2017-1712

    Last Modified: 21 Nov 2024

    "A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a vulnerable TLS stack implementation to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions."

    Published: 1 Jul 2020
    6.1
    Medium

    CVE-2017-1659

    Last Modified: 21 Nov 2024

    "HCL iNotes is susceptible to a Cross-Site Scripting (XSS) Vulnerability. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials."

    Published: 1 Jul 2020
    5.3
    Medium

    CVE-2020-6261

    Last Modified: 21 Nov 2024

    SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. The readability of the trace file is impaired.

    Published: 1 Jul 2020
    7.5
    High

    CVE-2020-15478

    Last Modified: 21 Nov 2024

    The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors.

    Published: 1 Jul 2020
    9.1
    Critical

    CVE-2020-15471

    Last Modified: 26 Jan 2026

    In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.c.

    Published: 1 Jul 2020
    9.1
    Critical

    CVE-2020-15472

    Last Modified: 21 Nov 2024

    In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short.

    Published: 1 Jul 2020
    9.1
    Critical

    CVE-2020-15473

    Last Modified: 26 Jan 2026

    In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.

    Published: 1 Jul 2020
    9.8
    Critical

    CVE-2020-15474

    Last Modified: 21 Nov 2024

    In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.

    Published: 1 Jul 2020
    9.8
    Critical

    CVE-2020-15475

    Last Modified: 21 Nov 2024

    In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.

    Published: 1 Jul 2020
    7.5
    High

    CVE-2020-15476

    Last Modified: 21 Nov 2024

    In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.

    Published: 1 Jul 2020
    5.5
    Medium

    CVE-2020-15470

    Last Modified: 21 Nov 2024

    ffjpeg through 2020-02-24 has a heap-based buffer overflow in jfif_decode in jfif.c.

    Published: 1 Jul 2020
    9.8
    Critical

    CVE-2020-15468

    Last Modified: 21 Nov 2024

    Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter.

    Published: 1 Jul 2020
    4.3
    Medium

    CVE-2020-4029

    Last Modified: 21 Nov 2024

    The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center before version 8.5.5, from 8.6.0 before 8.7.2, and from 8.8.0 before 8.8.1 allows remote attackers to enumerate project names via an improper authorization vulnerability.

    Published: 1 Jul 2020
    4.7
    Medium

    CVE-2020-4027

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vulnerability in custom user macros. The affected versions are before version 7.4.5, and from version 7.5.0 before 7.5.1.

    Published: 1 Jul 2020
    4.8
    Medium

    CVE-2020-4025

    Last Modified: 21 Nov 2024

    The attachment download resource in Atlassian Jira Server and Data Center The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a rdf content type.

    Published: 1 Jul 2020
    5.4
    Medium

    CVE-2020-4024

    Last Modified: 21 Nov 2024

    The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a vnd.wap.xhtml+xml content type.

    Published: 1 Jul 2020
    6.1
    Medium

    CVE-2020-4022

    Last Modified: 21 Nov 2024

    The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a mixed multipart content type.

    Published: 1 Jul 2020
    6.1
    Medium

    CVE-2020-14169

    Last Modified: 21 Nov 2024

    The quick search component in Atlassian Jira Server and Data Center before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability

    Published: 1 Jul 2020
    5.9
    Medium

    CVE-2020-14168

    Last Modified: 21 Nov 2024

    The email client in Jira Server and Data Center before version 7.13.16, from 8.5.0 before 8.5.7, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to access outgoing emails between a Jira instance and the SMTP server via man-in-the-middle (MITM) vulnerability.

    Published: 1 Jul 2020
    7.5
    High

    CVE-2020-14167

    Last Modified: 21 Nov 2024

    The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 before 8.5.5, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to impact the application's availability via an Denial of Service (DoS) vulnerability.

    Published: 1 Jul 2020
    4.8
    Medium

    CVE-2020-14166

    Last Modified: 21 Nov 2024

    The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remote attackers with project administrator privileges to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by uploading a html file.

    Published: 1 Jul 2020
    5.3
    Medium

    CVE-2020-14165

    Last Modified: 21 Nov 2024

    The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote attackers to obtain information about custom project avatars names via an Improper authorization vulnerability.

    Published: 1 Jul 2020
    6.1
    Medium

    CVE-2020-14164

    Last Modified: 21 Nov 2024

    The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by pasting javascript code into the editor field.

    Published: 1 Jul 2020
    5.3
    Medium

    CVE-2019-20408

    Last Modified: 21 Nov 2024

    The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.

    Published: 1 Jul 2020
    7.5
    High

    CVE-2020-1045

    Last Modified: 23 Feb 2026

    <p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.</p> <p>The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.</p>

    Published: 1 Jul 2020
    9.8
    Critical

    CVE-2020-5902

    Last Modified: 27 Oct 2025

    In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.

    Published: 1 Jul 2020
    6.5
    Medium

    CVE-2020-5238

    Last Modified: 21 Nov 2024

    The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long time to process, causing a denial of service. This issue does not affect the upstream cmark project. The issue has been fixed in version 0.29.0.gfm.1.

    Published: 1 Jul 2020
    4.4
    Medium

    CVE-2020-5973

    Last Modified: 21 Nov 2024

    NVIDIA Virtual GPU Manager and the guest drivers contain a vulnerability in vGPU plugin, in which there is the potential to execute privileged operations, which may lead to denial of service. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).

    Published: 30 Jun 2020
    7.1
    High

    CVE-2020-5970

    Last Modified: 21 Nov 2024

    NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, which may lead to tampering or denial of service. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).

    Published: 30 Jun 2020
    7.8
    High

    CVE-2020-5971

    Last Modified: 21 Nov 2024

    NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software reads from a buffer by using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer, which may lead to code execution, denial of service, escalation of privileges, or information disclosure. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).

    Published: 30 Jun 2020
    7.1
    High

    CVE-2020-5972

    Last Modified: 21 Nov 2024

    NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which local pointer variables are not initialized and may be freed later, which may lead to tampering or denial of service. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).

    Published: 30 Jun 2020
    6.3
    Medium

    CVE-2020-5969

    Last Modified: 21 Nov 2024

    NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which it validates a shared resource before using it, creating a race condition which may lead to denial of service or information disclosure. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).

    Published: 30 Jun 2020
    7.8
    High

    CVE-2020-5968

    Last Modified: 21 Nov 2024

    NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software does not restrict or incorrectly restricts operations within the boundaries of a resource that is accessed by using an index or pointer, such as memory or files, which may lead to code execution, denial of service, escalation of privileges, or information disclosure. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).

    Published: 30 Jun 2020
    8.8
    High

    CVE-2020-14947

    Last Modified: 21 Nov 2024

    OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php because mib_file in plugins/main_sections/ms_config/ms_snmp_config.php is mishandled in get_mib_oid.

    Published: 30 Jun 2020
    8.8
    High

    CVE-2020-9414

    Last Modified: 21 Nov 2024

    The MFT admin service component of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center and TIBCO Managed File Transfer Internet Server contains a vulnerability that theoretically allows an authenticated user with specific permissions to obtain the session identifier of another user. The session identifier when replayed could provide administrative rights or file transfer permissions to the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center: versions 8.2.1 and below and TIBCO Managed File Transfer Internet Server: versions 8.2.1 and below.

    Published: 30 Jun 2020
    6.3
    Medium

    CVE-2020-9413

    Last Modified: 21 Nov 2024

    The MFT Browser file transfer client and MFT Browser admin client components of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center and TIBCO Managed File Transfer Internet Server contain a vulnerability that theoretically allows an attacker to craft an URL that will execute arbitrary commands on the affected system. If the attacker convinces an authenticated user with a currently active session to enter or click on the URL the commands will be executed on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center: versions 8.2.1 and below and TIBCO Managed File Transfer Internet Server: versions 8.2.1 and below.

    Published: 30 Jun 2020
    7.5
    High

    CVE-2020-12604

    Last Modified: 21 Nov 2024

    Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier is susceptible to increased memory usage in the case where an HTTP/2 client requests a large payload but does not send enough window updates to consume the entire stream and does not reset the stream.

    Published: 30 Jun 2020
    7.5
    High

    CVE-2020-12605

    Last Modified: 21 Nov 2024

    Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when processing HTTP/1.1 headers with long field names or requests with long URLs.

    Published: 30 Jun 2020
    7.5
    High

    CVE-2020-12603

    Last Modified: 21 Nov 2024

    Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when proxying HTTP/2 requests or responses with many small (i.e. 1 byte) data frames.

    Published: 30 Jun 2020
    7.5
    High

    CVE-2020-8663

    Last Modified: 21 Nov 2024

    Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and/or memory when accepting too many connections.

    Published: 30 Jun 2020
    7.3
    High

    CVE-2020-7049

    Last Modified: 21 Nov 2024

    Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection.

    Published: 30 Jun 2020
    7.5
    High

    CVE-2020-14474

    Last Modified: 21 Nov 2024

    The Cellebrite UFED physical device 5.0 through 7.5.0.845 relies on key material hardcoded within both the executable code supporting the decryption process, and within the encrypted files themselves by using a key enveloping technique. The recovered key material is the same for every device running the same version of the software, and does not appear to be changed with each new build. It is possible to reconstruct the decryption process using the hardcoded key material and obtain easy access to otherwise protected data.

    Published: 30 Jun 2020
    6.1
    Medium

    CVE-2020-15307

    Last Modified: 21 Nov 2024

    Nozomi Guardian before 19.0.4 allows attackers to achieve stored XSS (in the web front end) by leveraging the ability to create a custom field with a crafted field name.

    Published: 30 Jun 2020
    7.8
    High

    CVE-2020-14482

    Last Modified: 21 Nov 2024

    Delta Industrial Automation DOPSoft, Version 4.00.08.15 and prior. Opening a specially crafted project file may overflow the heap, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.

    Published: 30 Jun 2020
    7.4
    High

    CVE-2020-15087

    Last Modified: 21 Nov 2024

    In Presto before version 337, authenticated users can bypass authorization checks by directly accessing internal APIs. This impacts Presto server installations with secure internal communication configured. This does not affect installations that have not configured secure internal communication, as these installations are inherently insecure. This only affects Presto server installations. This does NOT affect clients such as the CLI or JDBC driver. This vulnerability has been fixed in version 337. Additionally, this issue can be mitigated by blocking network access to internal APIs on the coordinator and workers.

    Published: 30 Jun 2020