CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2020-9797

    Last Modified: 21 Nov 2024

    An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to determine another application's memory layout.

    Published: 9 Jun 2020
    4.6
    Medium

    CVE-2020-9792

    Last Modified: 21 Nov 2024

    A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. A USB device may be able to cause a denial of service.

    Published: 9 Jun 2020
    6.5
    Medium

    CVE-2020-3882

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. Importing a maliciously crafted calendar invitation may exfiltrate user information.

    Published: 9 Jun 2020
    4.3
    Medium

    CVE-2020-13266

    Last Modified: 21 Nov 2024

    Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permissions of other users' deploy keys under certain conditions

    Published: 9 Jun 2020
    5.5
    Medium

    CVE-2020-10767

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel before 5.8-rc1 in the implementation of the Enhanced IBPB (Indirect Branch Prediction Barrier). The IBPB mitigation will be disabled when STIBP is not available or when the Enhanced Indirect Branch Restricted Speculation (IBRS) is available. This flaw allows a local attacker to perform a Spectre V2 style attack when this configuration is active. The highest threat from this vulnerability is to confidentiality.

    Published: 9 Jun 2020
    5.5
    Medium

    CVE-2020-10768

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function, where it can be used to enable indirect branch speculation after it has been disabled. This call incorrectly reports it as being 'force disabled' when it is not and opens the system to Spectre v2 attacks. The highest threat from this vulnerability is to confidentiality.

    Published: 9 Jun 2020
    4.8
    Medium

    CVE-2020-13980

    Last Modified: 21 Nov 2024

    OpenCart 3.0.3.3 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section because of a lack of entity encoding. NOTE: this issue exists because of an incomplete fix for CVE-2020-10596. The vendor states "this is not a massive issue as you are still required to be logged into the admin.

    Published: 9 Jun 2020
    8.8
    High

    CVE-2020-13976

    Last Modified: 21 Nov 2024

    An issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary commands via shell metacharacters in the host field of the ping command. Exploitation through CSRF might be possible. NOTE: software maintainers consider the report invalid because it refers to an old software version, requires administrative privileges, and does not provide access beyond that already available to administrative users

    Published: 9 Jun 2020
    4.9
    Medium

    CVE-2020-13977

    Last Modified: 21 Nov 2024

    Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson.cgi files. NOTE: this vulnerability has been mistakenly associated with CVE-2020-1408.

    Published: 9 Jun 2020
    7.2
    High

    CVE-2020-13978

    Last Modified: 21 Nov 2024

    Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute arbitrary OS commands via the Theme Module by visiting the admin/index.php?id=themes&action=edit_chunk URI. NOTE: there is no indication that the Edit Chunk feature was intended to prevent an administrator from using PHP's exec feature

    Published: 9 Jun 2020
    8.8
    High

    CVE-2020-5589

    Last Modified: 21 Nov 2024

    SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SP600N with firmware versions prior to 4.5.2 have vulnerability that someone within the Bluetooth range can make the Bluetooth pairing and operate such as changing volume of the product.

    Published: 9 Jun 2020
    6.1
    Medium

    CVE-2020-13973

    Last Modified: 21 Nov 2024

    OWASP json-sanitizer before 1.2.1 allows XSS. An attacker who controls a substring of the input JSON, and controls another substring adjacent to a SCRIPT element in which the output is embedded as JavaScript, may be able to confuse the HTML parser as to where the SCRIPT element ends, and cause non-script content to be interpreted as JavaScript.

    Published: 9 Jun 2020
    6.1
    Medium

    CVE-2020-13964

    Last Modified: 21 Nov 2024

    An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.

    Published: 9 Jun 2020
    6.1
    Medium

    CVE-2020-13965

    Last Modified: 4 Nov 2025

    An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.

    Published: 9 Jun 2020
    8.1
    High

    CVE-2020-14305

    Last Modified: 21 Nov 2024

    An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

    Published: 9 Jun 2020
    9.8
    Critical

    CVE-2020-9633

    Last Modified: 21 Nov 2024

    Adobe Flash Player Desktop Runtime 32.0.0.371 and earlier, Adobe Flash Player for Google Chrome 32.0.0.371 and earlier, and Adobe Flash Player for Microsoft Edge and Internet Explorer 32.0.0.330 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 9 Jun 2020
    7.5
    High

    CVE-2020-13962

    Last Modified: 21 Nov 2024

    Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions, an unrelated session may be disconnected when any handshake fails. (Mumble 1.3.1 is not affected, regardless of the Qt version.)

    Published: 8 Jun 2020
    7.4
    High

    CVE-2020-4041

    Last Modified: 21 Nov 2024

    In Bolt CMS before version 3.7.1, the filename of uploaded files was vulnerable to stored XSS. It is not possible to inject javascript code in the file name when creating/uploading the file. But, once created/uploaded, it can be renamed to inject the payload in it. Additionally, the measures to prevent renaming the file to disallowed filename extensions could be circumvented. This is fixed in Bolt 3.7.1.

    Published: 8 Jun 2020
    8.6
    High

    CVE-2020-4040

    Last Modified: 21 Nov 2024

    Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by the admins, developers, chief-editors, and editors, who are authorized to create content in the application. But due to lack of proper CSRF protection, unauthorized users could generate a preview. This has been fixed in Bolt 3.7.1

    Published: 8 Jun 2020
    7.4
    High

    CVE-2020-4038

    Last Modified: 21 Nov 2024

    GraphQL Playground (graphql-playground-html NPM package) before version 1.6.22 have a severe XSS Reflection attack vulnerability. All unsanitized user input passed into renderPlaygroundPage() method could trigger this vulnerability. This has been patched in graphql-playground-html version 1.6.22. Note that some of the associated dependent middleware packages are also affected including but not limited to graphql-playground-middleware-express before version 1.7.16, graphql-playground-middleware-koa before version 1.6.15, graphql-playground-middleware-lambda before version 1.7.17, and graphql-playground-middleware-hapi before 1.6.13.

    Published: 8 Jun 2020
    7.5
    High

    CVE-2020-13960

    Last Modified: 21 Nov 2024

    D-Link DSL 2730-U IN_1.10 and IN_1.11 and DIR-600M 3.04 devices have the domain.name string in the DNS resolver search path by default, which allows remote attackers to provide valid DNS responses (and also offer Internet services such as HTTP) for names that otherwise would have had an NXDOMAIN error, by registering a subdomain of the domain.name domain name.

    Published: 8 Jun 2020
    7.8
    High

    CVE-2020-13884

    Last Modified: 21 Nov 2024

    Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the uninstallation of the application.

    Published: 8 Jun 2020
    7.8
    High

    CVE-2020-13885

    Last Modified: 21 Nov 2024

    Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the application.

    Published: 8 Jun 2020
    4.6
    Medium

    CVE-2019-19412

    Last Modified: 21 Nov 2024

    Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the Talkback mode and can perform some operations to install a third-Party application. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-frp-en.

    Published: 8 Jun 2020
    7.8
    High

    CVE-2020-13428

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file.

    Published: 8 Jun 2020
    7.5
    High

    CVE-2020-13432

    Last Modified: 21 Nov 2024

    rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer write access violation via concurrent HTTP requests with a long URI or long HTTP headers.

    Published: 8 Jun 2020
    4.4
    Medium

    CVE-2020-13696

    Last Modified: 21 Nov 2024

    An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local attacker with access to the v4l-conf setuid-root program to test for the existence of arbitrary files and to trigger an open on arbitrary files with mode O_RDWR. To achieve this, relative path components need to be added to the device path, as demonstrated by a v4l-conf -c /dev/../root/.bash_history command.

    Published: 8 Jun 2020
    5.4
    Medium

    CVE-2020-8954

    Last Modified: 21 Nov 2024

    OpenSearch Web browser 1.0.4.9 allows Intent Scheme Hijacking.[a link that opens another app in the browser can be manipulated]

    Published: 8 Jun 2020
    9.8
    Critical

    CVE-2020-12800

    Last Modified: 21 Nov 2024

    The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.

    Published: 8 Jun 2020
    7.5
    High

    CVE-2020-5304

    Last Modified: 21 Nov 2024

    The dashboard in WhiteSource Application Vulnerability Management (AVM) before version 20.4.1 allows Log Injection via a %0A%0D substring in the idp parameter to the /saml/login URI. This closes the current log and creates a new log with one line of data. The attacker can also insert malicious data and false entries.

    Published: 8 Jun 2020
    7.5
    High

    CVE-2020-13625

    Last Modified: 21 Nov 2024

    PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.

    Published: 8 Jun 2020
    7.8
    High

    CVE-2020-13866

    Last Modified: 21 Nov 2024

    WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges by replacing an executable file with a Trojan horse.

    Published: 8 Jun 2020
    3.5
    Low

    CVE-2020-1775

    Last Modified: 21 Nov 2024

    BCC recipients in mails sent from OTRS are visible in article detail on external interface. This issue affects OTRS: 8.0.3 and prior versions, 7.0.17 and prior versions.

    Published: 8 Jun 2020
    7.5
    High

    CVE-2020-9040

    Last Modified: 21 Nov 2024

    Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intended peer. An attacker can leverage this flaw by crafting a cryptographically valid certificate that will be accepted by Java SDK's Netty component due to missing hostname verification.

    Published: 8 Jun 2020
    7.5
    High

    CVE-2020-9041

    Last Modified: 21 Nov 2024

    In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text search endpoints are vulnerable to the Slowloris denial-of-service attack because they don't more aggressively terminate slow connections.

    Published: 8 Jun 2020
    8.8
    High

    CVE-2020-9042

    Last Modified: 21 Nov 2024

    In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to check the results of a REST API request.

    Published: 8 Jun 2020
    9.8
    Critical

    CVE-2020-9099

    Last Modified: 21 Nov 2024

    Huawei products IPS Module; NGFW Module; NIP6300; NIP6600; NIP6800; Secospace USG6300; Secospace USG6500; Secospace USG6600; USG9500 with versions of V500R001C00; V500R001C20; V500R001C30; V500R001C50; V500R001C60; V500R001C80; V500R005C00; V500R005C10; V500R005C20; V500R002C00; V500R002C10; V500R002C20; V500R002C30 have an improper authentication vulnerability. Attackers need to perform some operations to exploit the vulnerability. Successful exploit may obtain certain permissions on the device.

    Published: 8 Jun 2020
    8.8
    High

    CVE-2020-6110

    Last Modified: 21 Nov 2024

    An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code snippets. A specially crafted chat message can cause an arbitrary binary planting which could be abused to achieve arbitrary code execution. An attacker needs to send a specially crafted message to a target user or a group to trigger this vulnerability. For the most severe effect, target user interaction is required.

    Published: 8 Jun 2020
    9.8
    Critical

    CVE-2020-6109

    Last Modified: 21 Nov 2024

    An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs. A specially crafted chat message can cause an arbitrary file write, which could potentially be abused to achieve arbitrary code execution. An attacker needs to send a specially crafted message to a target user or a group to exploit this vulnerability.

    Published: 8 Jun 2020
    9.9
    Critical

    CVE-2020-8180

    Last Modified: 21 Nov 2024

    A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator.

    Published: 8 Jun 2020
    7.4
    High

    CVE-2020-4529

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 182713.

    Published: 8 Jun 2020
    9.6
    Critical

    CVE-2020-12773

    Last Modified: 21 Nov 2024

    A security misconfiguration vulnerability exists in the SDK of some Realtek ADSL/PON Modem SoC firmware, which allows attackers using a default password to execute arbitrary commands remotely via the build-in network monitoring tool.

    Published: 8 Jun 2020
    5
    Medium

    CVE-2020-10761

    Last Modified: 21 Nov 2024

    An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.

    Published: 8 Jun 2020
    5.3
    Medium

    CVE-2020-12802

    Last Modified: 21 Nov 2024

    LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where remote graphic links loaded from docx documents were omitted from this protection prior to version 6.4.4. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

    Published: 8 Jun 2020
    6.5
    Medium

    CVE-2020-12803

    Last Modified: 21 Nov 2024

    ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

    Published: 8 Jun 2020
    6.7
    Medium

    CVE-2020-15436

    Last Modified: 21 Nov 2024

    Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field.

    Published: 8 Jun 2020
    7.5
    High

    CVE-2020-12695

    Last Modified: 21 Nov 2024

    The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

    Published: 8 Jun 2020
    6.1
    Medium

    CVE-2020-24303

    Last Modified: 21 Nov 2024

    Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

    Published: 8 Jun 2020
    7.3
    High

    CVE-2020-13912

    Last Modified: 21 Nov 2024

    SolarWinds Advanced Monitoring Agent before 10.8.9 allows local users to gain privileges via a Trojan horse .exe file, because everyone can write to a certain .exe file.

    Published: 7 Jun 2020
    9.1
    Critical

    CVE-2020-13910

    Last Modified: 21 Nov 2024

    Pengutronix Barebox through v2020.05.0 has an out-of-bounds read in nfs_read_reply in net/nfs.c because a field of an incoming network packet is directly used as a length field without any bounds check.

    Published: 7 Jun 2020