CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2020-9610

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a null pointer vulnerability. Successful exploitation could lead to application denial-of-service.

    Published: 25 Jun 2020
    8.8
    High

    CVE-2020-9612

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9614

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a security bypass vulnerability. Successful exploitation could lead to security feature bypass.

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9592

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a security bypass vulnerability. Successful exploitation could lead to security feature bypass.

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9657

    Last Modified: 21 Nov 2024

    Adobe Premiere Rush versions 1.5.12 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9655

    Last Modified: 21 Nov 2024

    Adobe Premiere Rush versions 1.5.12 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9656

    Last Modified: 21 Nov 2024

    Adobe Premiere Rush versions 1.5.12 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9652

    Last Modified: 21 Nov 2024

    Adobe Premiere Pro versions 14.2 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9654

    Last Modified: 21 Nov 2024

    Adobe Premiere Pro versions 14.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9653

    Last Modified: 21 Nov 2024

    Adobe Premiere Pro versions 14.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9659

    Last Modified: 21 Nov 2024

    Adobe Audition versions 13.0.6 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9658

    Last Modified: 21 Nov 2024

    Adobe Audition versions 13.0.6 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9660

    Last Modified: 21 Nov 2024

    Adobe After Effects versions 17.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9638

    Last Modified: 21 Nov 2024

    Adobe After Effects versions 17.1 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9661

    Last Modified: 21 Nov 2024

    Adobe After Effects versions 17.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9637

    Last Modified: 21 Nov 2024

    Adobe After Effects versions 17.1 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9662

    Last Modified: 21 Nov 2024

    Adobe After Effects versions 17.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9639

    Last Modified: 21 Nov 2024

    Adobe Illustrator versions 24.1.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9640

    Last Modified: 21 Nov 2024

    Adobe Illustrator versions 24.1.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9641

    Last Modified: 21 Nov 2024

    Adobe Illustrator versions 24.1.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9575

    Last Modified: 21 Nov 2024

    Adobe Illustrator versions 24.1.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-9642

    Last Modified: 21 Nov 2024

    Adobe Illustrator versions 24.1.2 and earlier have a buffer errors vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 25 Jun 2020
    5.5
    Medium

    CVE-2020-9666

    Last Modified: 24 Aug 2026

    Adobe Campaign Classic before 20.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 25 Jun 2020
    5.3
    Medium

    CVE-2020-4072

    Last Modified: 21 Nov 2024

    In generator-jhipster-kotlin version 1.6.0 log entries are created for invalid password reset attempts. As the email is provided by a user and the api is public this can be used by an attacker to forge log entries. This is vulnerable to https://cwe.mitre.org/data/definitions/117.html This problem affects only application generated with jwt or session authentication. Applications using oauth are not vulnerable. This issue has been fixed in version 1.7.0.

    Published: 25 Jun 2020
    7.5
    High

    CVE-2020-15302

    Last Modified: 21 Nov 2024

    In Argent RecoveryManager before 0xdc350d09f71c48c5D22fBE2741e4d6A03970E192, the executeRecovery function does not require any signatures in the zero-guardian case, which allows attackers to cause a denial of service (locking) or a takeover.

    Published: 25 Jun 2020
    4.8
    Medium

    CVE-2020-9437

    Last Modified: 21 Nov 2024

    SecureAuth.aspx in SecureAuth IdP 9.3.0 suffers from a client-side template injection that allows for script execution, in the same manner as XSS.

    Published: 25 Jun 2020
    8.8
    High

    CVE-2019-19505

    Last Modified: 21 Nov 2024

    Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the "Wireless" section in the web-UI. By sending a specially crafted hostname, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.

    Published: 25 Jun 2020
    7.5
    High

    CVE-2019-19506

    Last Modified: 21 Nov 2024

    Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd" process. By sending a specially crafted UDP packet, an attacker could exploit this vulnerability to cause the device to reboot.

    Published: 25 Jun 2020
    8.8
    High

    CVE-2019-16213

    Last Modified: 21 Nov 2024

    Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted string, an attacker could modify the device name of an attached PLC adapter to inject and execute arbitrary commands on the system with root privileges.

    Published: 25 Jun 2020
    8.1
    High

    CVE-2020-11538

    Last Modified: 21 Nov 2024

    In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.

    Published: 25 Jun 2020
    6.1
    Medium

    CVE-2020-7355

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) vulnerability in the 'notes' field of a discovered scan asset in Rapid7 Metasploit Pro allows an attacker with a specially-crafted network service of a scan target store an XSS sequence in the Metasploit Pro console, which will trigger when the operator views the record of that scanned host in the Metasploit Pro interface. This issue affects Rapid7 Metasploit Pro version 4.17.1-20200427 and prior versions, and is fixed in Metasploit Pro version 4.17.1-20200514. See also CVE-2020-7354, which describes a similar issue, but involving the generated 'host' field of a discovered scan asset.

    Published: 25 Jun 2020
    6.1
    Medium

    CVE-2020-7354

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) vulnerability in the 'host' field of a discovered scan asset in Rapid7 Metasploit Pro allows an attacker with a specially-crafted network service of a scan target to store an XSS sequence in the Metasploit Pro console, which will trigger when the operator views the record of that scanned host in the Metasploit Pro interface. This issue affects Rapid7 Metasploit Pro version 4.17.1-20200427 and prior versions, and is fixed in Metasploit Pro version 4.17.1-20200514. See also CVE-2020-7355, which describes a similar issue, but involving the generated 'notes' field of a discovered scan asset.

    Published: 25 Jun 2020
    10
    Critical

    CVE-2018-21268

    Last Modified: 21 Nov 2024

    The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the Child.exec() method, which is considered to be not entirely safe, is used. In particular, an OS command can be placed after a newline character.

    Published: 25 Jun 2020
    5.5
    Medium

    CVE-2020-3971

    Last Modified: 21 Nov 2024

    VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x before 15.0.2), and Fusion (11.x before 11.0.2) contain a heap overflow vulnerability in the vmxnet3 virtual network adapter. A malicious actor with local access to a virtual machine with a vmxnet3 network adapter present may be able to read privileged information contained in physical memory.

    Published: 25 Jun 2020
    5.5
    Medium

    CVE-2020-3965

    Last Modified: 21 Nov 2024

    VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the XHCI USB controller. A malicious actor with local access to a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.

    Published: 25 Jun 2020
    4.7
    Medium

    CVE-2020-3964

    Last Modified: 21 Nov 2024

    VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the EHCI USB controller. A malicious actor with local access to a virtual machine may be able to read privileged information contained in the hypervisor's memory. Additional conditions beyond the attacker's control need to be present for exploitation to be possible.

    Published: 25 Jun 2020
    5.5
    Medium

    CVE-2020-3963

    Last Modified: 21 Nov 2024

    VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a use-after-free vulnerability in PVNVRAM. A malicious actor with local access to a virtual machine may be able to read privileged information contained in physical memory.

    Published: 25 Jun 2020
    7.5
    High

    CVE-2020-3966

    Last Modified: 21 Nov 2024

    VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a heap-overflow due to a race condition issue in the USB 2.0 controller (EHCI). A malicious actor with local access to a virtual machine may be able to exploit this vulnerability to execute code on the hypervisor from a virtual machine. Additional conditions beyond the attacker's control must be present for exploitation to be possible.

    Published: 25 Jun 2020
    8.2
    High

    CVE-2020-3968

    Last Modified: 21 Nov 2024

    VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds write vulnerability in the USB 3.0 controller (xHCI). A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to crash the virtual machine's vmx process leading to a denial of service condition or execute code on the hypervisor from a virtual machine. Additional conditions beyond the attacker's control must be present for exploitation to be possible.

    Published: 25 Jun 2020
    7.5
    High

    CVE-2020-3967

    Last Modified: 21 Nov 2024

    VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a heap-overflow vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local access to a virtual machine may be able to exploit this vulnerability to execute code on the hypervisor from a virtual machine. Additional conditions beyond the attacker's control must be present for exploitation to be possible.

    Published: 25 Jun 2020
    3.8
    Low

    CVE-2020-3970

    Last Modified: 21 Nov 2024

    VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in the Shader functionality. A malicious actor with non-administrative local access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to crash the virtual machine's vmx process leading to a partial denial of service condition.

    Published: 25 Jun 2020
    5.3
    Medium

    CVE-2020-11735

    Last Modified: 21 Nov 2024

    The private-key operations in ecc.c in wolfSSL before 4.4.0 do not use a constant-time modular inverse when mapping to affine coordinates, aka a "projective coordinates leak."

    Published: 25 Jun 2020
    5.9
    Medium

    CVE-2020-15047

    Last Modified: 21 Nov 2024

    MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to spoof SMTP servers.

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-5964

    Last Modified: 21 Nov 2024

    NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the service host component, in which the application resources integrity check may be missed. Such an attack may lead to code execution, denial of service or information disclosure.

    Published: 25 Jun 2020
    5.5
    Medium

    CVE-2020-5965

    Last Modified: 21 Nov 2024

    NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the DirectX 11 user mode driver (nvwgf2um/x.dll), in which a specially crafted shader can cause an out of bounds access, leading to denial of service.

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-5963

    Last Modified: 21 Nov 2024

    NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to code execution, denial of service, or information disclosure.

    Published: 25 Jun 2020
    5.5
    Medium

    CVE-2020-10727

    Last Modified: 15 Jun 2026

    A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executing the `resetUsers` operation. A local attacker can use this flaw to read the contents of the Artemis shadow file.

    Published: 25 Jun 2020
    7.5
    High

    CVE-2020-11996

    Last Modified: 21 Nov 2024

    A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.

    Published: 25 Jun 2020
    5.5
    Medium

    CVE-2020-10177

    Last Modified: 21 Nov 2024

    Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.

    Published: 25 Jun 2020
    5.5
    Medium

    CVE-2020-10994

    Last Modified: 21 Nov 2024

    In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.

    Published: 25 Jun 2020