CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2020-1813

    Last Modified: 21 Nov 2024

    HUAWEI P30 smart phone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authentication vulnerability. Due to improper authentication of specific interface, in specific scenario attackers could access specific interface without authentication. Successful exploit could allow the attacker to perform unauthorized operations.

    Published: 15 Jun 2020
    5.5
    Medium

    CVE-2020-0539

    Last Modified: 21 Nov 2024

    Path traversal in subsystem for Intel(R) DAL software for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32, 14.0.33 and Intel(R) TXE versions before 3.1.75, 4.0.25 may allow an unprivileged user to potentially enable denial of service via local access.

    Published: 15 Jun 2020
    5.3
    Medium

    CVE-2020-8674

    Last Modified: 21 Nov 2024

    Out-of-bounds read in DHCPv6 subsystem in Intel(R) AMT and Intel(R)ISM versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64 and 14.0.33 may allow an unauthenticated user to potentially enable information disclosure via network access.

    Published: 15 Jun 2020
    4.4
    Medium

    CVE-2020-0545

    Last Modified: 21 Nov 2024

    Integer overflow in subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77 and Intel(R) TXE versions before 3.1.75, 4.0.25 and Intel(R) Server Platform Services (SPS) versions before SPS_E5_04.01.04.380.0, SPS_SoC-X_04.00.04.128.0, SPS_SoC-A_04.00.04.211.0, SPS_E3_04.01.04.109.0, SPS_E3_04.08.04.070.0 may allow a privileged user to potentially enable denial of service via local access.

    Published: 15 Jun 2020
    4.9
    Medium

    CVE-2020-0537

    Last Modified: 21 Nov 2024

    Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow a privileged user to potentially enable denial of service via network access.

    Published: 15 Jun 2020
    7.5
    High

    CVE-2020-0536

    Last Modified: 21 Nov 2024

    Improper input validation in the DAL subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32,14.0.33 and Intel(R) TXE versions before 3.1.75 and 4.0.25 may allow an unauthenticated user to potentially enable information disclosure via network access.

    Published: 15 Jun 2020
    7.5
    High

    CVE-2020-0540

    Last Modified: 21 Nov 2024

    Insufficiently protected credentials in Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access.

    Published: 15 Jun 2020
    5.3
    Medium

    CVE-2020-0535

    Last Modified: 21 Nov 2024

    Improper input validation in Intel(R) AMT versions before 11.8.76, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access.

    Published: 15 Jun 2020
    6.5
    Medium

    CVE-2020-0531

    Last Modified: 21 Nov 2024

    Improper input validation in Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an authenticated user to potentially enable information disclosure via network access.

    Published: 15 Jun 2020
    7.5
    High

    CVE-2020-0597

    Last Modified: 21 Nov 2024

    Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 14.0.33 may allow an unauthenticated user to potentially enable denial of service via network access.

    Published: 15 Jun 2020
    6.7
    Medium

    CVE-2020-0541

    Last Modified: 21 Nov 2024

    Out-of-bounds write in subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 15 Jun 2020
    7.1
    High

    CVE-2020-0532

    Last Modified: 21 Nov 2024

    Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access.

    Published: 15 Jun 2020
    6.8
    Medium

    CVE-2020-0566

    Last Modified: 21 Nov 2024

    Improper Access Control in subsystem for Intel(R) TXE versions before 3.175 and 4.0.25 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

    Published: 15 Jun 2020
    6.7
    Medium

    CVE-2020-0533

    Last Modified: 21 Nov 2024

    Reversible one-way hash in Intel(R) CSME versions before 11.8.76, 11.12.77 and 11.22.77 may allow a privileged user to potentially enable escalation of privilege, denial of service or information disclosure via local access.

    Published: 15 Jun 2020
    7.5
    High

    CVE-2020-0534

    Last Modified: 21 Nov 2024

    Improper input validation in the DAL subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow an unauthenticated user to potentially enable denial of service via network access.

    Published: 15 Jun 2020
    7.5
    High

    CVE-2020-0538

    Last Modified: 21 Nov 2024

    Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable denial of service via network access.

    Published: 15 Jun 2020
    7.5
    High

    CVE-2020-0596

    Last Modified: 21 Nov 2024

    Improper input validation in DHCPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access.

    Published: 15 Jun 2020
    7.8
    High

    CVE-2020-0542

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow an authenticated user to potentially enable escalation of privilege, information disclosure or denial of service via local access.

    Published: 15 Jun 2020
    7.8
    High

    CVE-2020-0586

    Last Modified: 21 Nov 2024

    Improper initialization in subsystem for Intel(R) SPS versions before SPS_E3_04.01.04.109.0 and SPS_E3_04.08.04.070.0 may allow an authenticated user to potentially enable escalation of privilege and/or denial of service via local access.

    Published: 15 Jun 2020
    9.8
    Critical

    CVE-2020-0595

    Last Modified: 21 Nov 2024

    Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

    Published: 15 Jun 2020
    9.8
    Critical

    CVE-2020-0594

    Last Modified: 21 Nov 2024

    Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

    Published: 15 Jun 2020
    7.8
    High

    CVE-2020-0529

    Last Modified: 21 Nov 2024

    Improper initialization in BIOS firmware for 8th, 9th and 10th Generation Intel(R) Core(TM) Processor families may allow an unauthenticated user to potentially enable escalation of privilege via local access.

    Published: 15 Jun 2020
    7.8
    High

    CVE-2020-0528

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in BIOS firmware for 7th, 8th, 9th and 10th Generation Intel(R) Core(TM) Processor families may allow an authenticated user to potentially enable escalation of privilege and/or denial of service via local access.

    Published: 15 Jun 2020
    6.8
    Medium

    CVE-2020-8675

    Last Modified: 21 Nov 2024

    Insufficient control flow management in firmware build and signing tool for Intel(R) Innovation Engine before version 1.0.859 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

    Published: 15 Jun 2020
    4.4
    Medium

    CVE-2020-0527

    Last Modified: 21 Nov 2024

    Insufficient control flow management in firmware for some Intel(R) Data Center SSDs may allow a privileged user to potentially enable information disclosure via local access.

    Published: 15 Jun 2020
    5.4
    Medium

    CVE-2020-14146

    Last Modified: 21 Nov 2024

    KumbiaPHP through 1.1.1, in Development mode, allows XSS via the public/pages/kumbia PATH_INFO.

    Published: 15 Jun 2020
    7.5
    High

    CVE-2020-4494

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow an attacker to bypass authentication due to improper session validation which can result in access to unauthorized resources. IBM X-Force ID: 182019.

    Published: 15 Jun 2020
    6.5
    Medium

    CVE-2020-4477

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 discloses highly sensitive information in plain text in the virgo log file which could be used in further attacks against the system. IBM X-Force ID: 181779.

    Published: 15 Jun 2020
    6.5
    Medium

    CVE-2020-4471

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an unauthenticated attacker to cause a denial of service or hijack DNS sessions by send a specially crafted HTTP command to the remote server. IBM X-Force ID: 181726.

    Published: 15 Jun 2020
    8
    High

    CVE-2020-4470

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the vulnerable server. IBM X-Force ID: 181725.

    Published: 15 Jun 2020
    9.8
    Critical

    CVE-2020-4469

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. This vulnerability is due to an incomplete fix for CVE-2020-4211. IBM X-Force ID: 181724.

    Published: 15 Jun 2020
    5.4
    Medium

    CVE-2020-4406

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 179488.

    Published: 15 Jun 2020
    9.8
    Critical

    CVE-2020-4216

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 175066.

    Published: 15 Jun 2020
    6.1
    Medium

    CVE-2019-19111

    Last Modified: 21 Nov 2024

    The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter.

    Published: 15 Jun 2020
    4.8
    Medium

    CVE-2019-19110

    Last Modified: 21 Nov 2024

    The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter.

    Published: 15 Jun 2020
    8.8
    High

    CVE-2019-19109

    Last Modified: 21 Nov 2024

    The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.

    Published: 15 Jun 2020
    6.1
    Medium

    CVE-2019-19112

    Last Modified: 21 Nov 2024

    The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php.

    Published: 15 Jun 2020
    8.8
    High

    CVE-2020-14076

    Last Modified: 21 Nov 2024

    TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action st_dev_connect, st_dev_disconnect, or st_dev_rconnect with a sufficiently long wan_type key.

    Published: 15 Jun 2020
    8.8
    High

    CVE-2020-14074

    Last Modified: 21 Nov 2024

    TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action kick_ban_wifi_mac_allow with a sufficiently long qcawifi.wifi0_vap0.maclist key.

    Published: 15 Jun 2020
    8.8
    High

    CVE-2020-14075

    Last Modified: 21 Nov 2024

    TRENDnet TEW-827DRU devices through 2.06B04 contain multiple command injections in apply.cgi via the action pppoe_connect, ru_pppoe_connect, or dhcp_connect with the key wan_ifname (or wan0_dns), allowing an authenticated user to run arbitrary commands on the device.

    Published: 15 Jun 2020
    8.8
    High

    CVE-2020-14077

    Last Modified: 21 Nov 2024

    TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action set_sta_enrollee_pin_wifi1 (or set_sta_enrollee_pin_wifi0) with a sufficiently long wps_sta_enrollee_pin key.

    Published: 15 Jun 2020
    8.8
    High

    CVE-2020-14078

    Last Modified: 21 Nov 2024

    TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action wifi_captive_portal_login with a sufficiently long REMOTE_ADDR key.

    Published: 15 Jun 2020
    8.8
    High

    CVE-2020-14079

    Last Modified: 21 Nov 2024

    TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action auto_up_fw (or auto_up_lp) with a sufficiently long update_file_name key.

    Published: 15 Jun 2020
    9.8
    Critical

    CVE-2020-14080

    Last Modified: 21 Nov 2024

    TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an unauthenticated user to execute arbitrary code by POSTing to apply_sec.cgi via the action ping_test with a sufficiently long ping_ipaddr key.

    Published: 15 Jun 2020
    8.8
    High

    CVE-2020-14081

    Last Modified: 21 Nov 2024

    TRENDnet TEW-827DRU devices through 2.06B04 contain multiple command injections in apply.cgi via the action send_log_email with the key auth_acname (or auth_passwd), allowing an authenticated user to run arbitrary commands on the device.

    Published: 15 Jun 2020
    9.8
    Critical

    CVE-2020-14067

    Last Modified: 21 Nov 2024

    The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files within a ZIP archive that may contain PHP code, in check_upload in lib/packages/extensions/extension.class.php and lib/packages/themes/theme.class.php.

    Published: 15 Jun 2020
    7.5
    High

    CVE-2019-17566

    Last Modified: 21 Nov 2024

    Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

    Published: 15 Jun 2020
    5.9
    Medium

    CVE-2020-14093

    Last Modified: 21 Nov 2024

    Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.

    Published: 15 Jun 2020
    7.7
    High

    CVE-2020-14147

    Last Modified: 21 Nov 2024

    An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stack-based buffer overflow. NOTE: this issue exists because of a CVE-2015-8080 regression.

    Published: 15 Jun 2020
    5.3
    Medium

    CVE-2020-14155

    Last Modified: 21 Nov 2024

    libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.

    Published: 15 Jun 2020