CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2020-15340

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded opt/axess/AXAssets/default_axess/axess/TR69/Handlers/turbolink/sshkeys/id_rsa SSH key.

    Published: 26 Jun 2020
    7.5
    High

    CVE-2020-15341

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API.

    Published: 26 Jun 2020
    5.3
    Medium

    CVE-2020-15342

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API.

    Published: 26 Jun 2020
    5.3
    Medium

    CVE-2020-15343

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API.

    Published: 26 Jun 2020
    5.3
    Medium

    CVE-2020-15344

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_user_id_and_key API.

    Published: 26 Jun 2020
    5.3
    Medium

    CVE-2020-15345

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_instances_for_update API.

    Published: 26 Jun 2020
    5.3
    Medium

    CVE-2020-15346

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a /live/GLOBALS API with the CLOUDCNM key.

    Published: 26 Jun 2020
    9.8
    Critical

    CVE-2020-15347

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account.

    Published: 26 Jun 2020
    5.3
    Medium

    CVE-2020-15325

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication.

    Published: 26 Jun 2020
    5.3
    Medium

    CVE-2020-15326

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded certificate for Ejabberd in ejabberd.pem.

    Published: 26 Jun 2020
    7.5
    High

    CVE-2020-15327

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.

    Published: 26 Jun 2020
    5.3
    Medium

    CVE-2020-15328

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions.

    Published: 26 Jun 2020
    5.3
    Medium

    CVE-2020-15329

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak Data.fs permissions.

    Published: 26 Jun 2020
    5.3
    Medium

    CVE-2020-15330

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded APP_KEY in /opt/axess/etc/default/axess.

    Published: 26 Jun 2020
    9.8
    Critical

    CVE-2020-15331

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.

    Published: 26 Jun 2020
    9.8
    Critical

    CVE-2020-15348

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows use of live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids= for eval injection of Python code.

    Published: 26 Jun 2020
    5.9
    Medium

    CVE-2020-4565

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an attacker to obtain sensitive information due to insecure communications being used between the application and server. IBM X-Force ID: 183935.

    Published: 26 Jun 2020
    5.4
    Medium

    CVE-2020-4223

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 175121.

    Published: 26 Jun 2020
    6.3
    Medium

    CVE-2019-4650

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170961.

    Published: 26 Jun 2020
    6.1
    Medium

    CVE-2020-15016

    Last Modified: 21 Nov 2024

    NeDi 1.9C is vulnerable to reflected cross-site scripting. The Other-Converter.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the txt GET parameter.

    Published: 26 Jun 2020
    6.1
    Medium

    CVE-2020-15017

    Last Modified: 21 Nov 2024

    NeDi 1.9C is vulnerable to reflected cross-site scripting. The Devices-Config.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the sta GET parameter.

    Published: 26 Jun 2020
    —
    Unknown

    CVE-2020-15311

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-4080. Reason: This candidate is a duplicate of CVE-2008-4080.2. Notes: All CVE users should reference CVE-2008-4080.2 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 26 Jun 2020
    7.2
    High

    CVE-2020-15308

    Last Modified: 21 Nov 2024

    Support Incident Tracker (aka SiT! or SiTracker) 3.67 p2 allows post-authentication SQL injection via the site_edit.php typeid or site parameter, the search_incidents_advanced.php search_title parameter, or the report_qbe.php criteriafield parameter.

    Published: 26 Jun 2020
    9.9
    Critical

    CVE-2020-15049

    Last Modified: 21 Nov 2024

    An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can succeed against the HTTP cache. The client sends an HTTP request with a Content-Length header containing "+\ "-" or an uncommon shell whitespace character prefix to the length field-value.

    Published: 26 Jun 2020
    5.5
    Medium

    CVE-2020-15304

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp, as demonstrated by a NULL pointer dereference.

    Published: 26 Jun 2020
    5.5
    Medium

    CVE-2020-15305

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp.

    Published: 26 Jun 2020
    5.5
    Medium

    CVE-2020-15306

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp.

    Published: 26 Jun 2020
    7.8
    High

    CVE-2020-5966

    Last Modified: 21 Nov 2024

    NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, in which a NULL pointer is dereferenced, leading to denial of service or potential escalation of privileges.

    Published: 25 Jun 2020
    4.7
    Medium

    CVE-2020-5967

    Last Modified: 21 Nov 2024

    NVIDIA Linux GPU Display Driver, all versions, contains a vulnerability in the UVM driver, in which a race condition may lead to a denial of service.

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9596

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a security bypass vulnerability. Successful exploitation could lead to security feature bypass.

    Published: 25 Jun 2020
    5.5
    Medium

    CVE-2020-9595

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an invalid memory access vulnerability. Successful exploitation could lead to information disclosure.

    Published: 25 Jun 2020
    8.8
    High

    CVE-2020-9597

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    5.5
    Medium

    CVE-2020-9598

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an invalid memory access vulnerability. Successful exploitation could lead to information disclosure.

    Published: 25 Jun 2020
    7.5
    High

    CVE-2020-9601

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 25 Jun 2020
    7.5
    High

    CVE-2020-9599

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9594

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.5
    High

    CVE-2020-9600

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 25 Jun 2020
    5.5
    Medium

    CVE-2020-9593

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an invalid memory access vulnerability. Successful exploitation could lead to information disclosure.

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9607

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9606

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    5.5
    Medium

    CVE-2020-9609

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 25 Jun 2020
    5.5
    Medium

    CVE-2020-9608

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9605

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    5.5
    Medium

    CVE-2020-9603

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9604

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    5.5
    Medium

    CVE-2020-9602

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 25 Jun 2020
    5.5
    Medium

    CVE-2020-9618

    Last Modified: 21 Nov 2024

    Adobe Audition versions 13.0.5 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9613

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a security bypass vulnerability. Successful exploitation could lead to security feature bypass.

    Published: 25 Jun 2020
    5.5
    Medium

    CVE-2020-9611

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a stack exhaustion vulnerability. Successful exploitation could lead to application denial-of-service.

    Published: 25 Jun 2020
    7
    High

    CVE-2020-9615

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a race condition vulnerability. Successful exploitation could lead to security feature bypass.

    Published: 25 Jun 2020