CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2020-6868

    Last Modified: 21 Nov 2024

    There is an input validation vulnerability in a PON terminal product of ZTE, which supports the creation of WAN connections through WEB management pages. The front-end limits the length of the WAN connection name that is created, but the HTTP proxy is available to be used to bypass the limitation. An attacker can exploit the vulnerability to tamper with the parameter value. This affects: ZTE F680 V9.0.10P1N6

    Published: 1 Jun 2020
    5.4
    Medium

    CVE-2020-4023

    Last Modified: 21 Nov 2024

    The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the committerFilter parameter.

    Published: 1 Jun 2020
    5.4
    Medium

    CVE-2020-4021

    Last Modified: 21 Nov 2024

    Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the XML export view.

    Published: 1 Jun 2020
    7.2
    High

    CVE-2020-4020

    Last Modified: 21 Nov 2024

    The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server instance that the Companion App is connected to, execute arbitrary .exe files via a Protection Mechanism Failure.

    Published: 1 Jun 2020
    7.8
    High

    CVE-2020-4019

    Last Modified: 21 Nov 2024

    The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable in place of the app's cmd.exe via a untrusted search path vulnerability.

    Published: 1 Jun 2020
    8.8
    High

    CVE-2020-4018

    Last Modified: 21 Nov 2024

    The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site request forgery (CSRF) vulnerability.

    Published: 1 Jun 2020
    5.3
    Medium

    CVE-2020-4017

    Last Modified: 21 Nov 2024

    The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get information about any configured Jira application links via an information disclosure vulnerability.

    Published: 1 Jun 2020
    5.3
    Medium

    CVE-2020-4016

    Last Modified: 21 Nov 2024

    The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get the ID of configured Jira application links via an information disclosure vulnerability.

    Published: 1 Jun 2020
    4.3
    Medium

    CVE-2020-4015

    Last Modified: 21 Nov 2024

    The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a information disclosure vulnerability.

    Published: 1 Jun 2020
    4.3
    Medium

    CVE-2020-4014

    Last Modified: 21 Nov 2024

    The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to remove another user's watching settings for a repository via an improper authorization vulnerability.

    Published: 1 Jun 2020
    5.4
    Medium

    CVE-2020-4013

    Last Modified: 21 Nov 2024

    The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the review objectives.

    Published: 1 Jun 2020
    7.7
    High

    CVE-2020-13822

    Last Modified: 21 Nov 2024

    The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.

    Published: 1 Jun 2020
    7.5
    High

    CVE-2020-0181

    Last Modified: 21 Nov 2024

    In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145075076

    Published: 1 Jun 2020
    6
    Medium

    CVE-2020-13401

    Last Modified: 21 Nov 2024

    An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.

    Published: 1 Jun 2020
    6.7
    Medium

    CVE-2020-13754

    Last Modified: 21 Nov 2024

    hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation.

    Published: 1 Jun 2020
    7.5
    High

    CVE-2020-0198

    Last Modified: 21 Nov 2024

    In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146428941

    Published: 1 Jun 2020
    6
    Medium

    CVE-2020-10749

    Last Modified: 21 Nov 2024

    A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

    Published: 1 Jun 2020
    6.5
    Medium

    CVE-2020-0182

    Last Modified: 21 Nov 2024

    In exif_entry_get_value of exif-entry.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147140917

    Published: 1 Jun 2020
    5.5
    Medium

    CVE-2020-12867

    Last Modified: 21 Nov 2024

    A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.

    Published: 1 Jun 2020
    6.3
    Medium

    CVE-2020-8555

    Last Modified: 21 Nov 2024

    The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from unprotected endpoints within the master's host network (such as link-local or loopback services).

    Published: 1 Jun 2020
    7.8
    High

    CVE-2020-14356

    Last Modified: 21 Nov 2024

    A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.

    Published: 31 May 2020
    6.7
    Medium

    CVE-2020-13776

    Last Modified: 9 Jun 2025

    systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000082.

    Published: 31 May 2020
    7.8
    High

    CVE-2020-8482

    Last Modified: 21 Nov 2024

    Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6.0.3.2 allows unauthenticated low privilege user to read file that contains confidential data

    Published: 29 May 2020
    7.5
    High

    CVE-2020-6937

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers to submit data which can lead to resource exhaustion.

    Published: 29 May 2020
    10
    Critical

    CVE-2020-11844

    Last Modified: 21 Nov 2024

    Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: - Hybrid Cloud Management. Versions 2018.05 to 2019.11. - ArcSight Investigate. versions 2.4.0, 3.0.0 and 3.1.0. - ArcSight Transformation Hub. versions 3.0.0, 3.1.0, 3.2.0. - ArcSight Interset. version 6.0.0. - ArcSight ESM (when ArcSight Fusion 1.0 is installed). version 7.2.1. - Service Management Automation (SMA). versions 2018.05 to 2020.02 - Operation Bridge Suite (Containerized). Versions 2018.05 to 2020.02. - Network Operation Management. versions 2017.11 to 2019.11. - Data Center Automation Containerized. versions 2018.05 to 2019.11 - Identity Intelligence. versions 1.1.0 and 1.1.1. The vulnerability could be exploited to provide unauthorized access to the Container Deployment Foundation.

    Published: 29 May 2020
    6.5
    Medium

    CVE-2020-7650

    Last Modified: 21 Nov 2024

    All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the following extensions: yaml, yml or json.

    Published: 29 May 2020
    7.5
    High

    CVE-2020-7654

    Last Modified: 21 Nov 2024

    All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level is set to DEBUG.

    Published: 29 May 2020
    6.5
    Medium

    CVE-2020-7648

    Last Modified: 21 Nov 2024

    All versions of snyk-broker before 4.72.2 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users who have access to Snyk's internal network by appending the URL with a fragment identifier and a whitelisted path e.g. `#package.json`

    Published: 29 May 2020
    4.3
    Medium

    CVE-2020-7651

    Last Modified: 21 Nov 2024

    All versions of snyk-broker before 4.79.0 are vulnerable to Arbitrary File Read. It allows partial file reads for users who have access to Snyk's internal network via patch history from GitHub Commits API.

    Published: 29 May 2020
    6.5
    Medium

    CVE-2020-7652

    Last Modified: 21 Nov 2024

    All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.

    Published: 29 May 2020
    6.5
    Medium

    CVE-2020-7653

    Last Modified: 21 Nov 2024

    All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network by creating symlinks to match whitelisted paths.

    Published: 29 May 2020
    2.4
    Low

    CVE-2020-1831

    Last Modified: 21 Nov 2024

    HUAWEI Mate 20 smartphones with versions earlier than 10.0.0.195(SP31C00E74R3P8) have an improper authorization vulnerability. The digital balance function does not sufficiently restrict the using time of certain user, successful exploit could allow the user break the limit of digital balance function after a series of operations with a PC.

    Published: 29 May 2020
    2.4
    Low

    CVE-2020-1833

    Last Modified: 21 Nov 2024

    Honor 9X smartphones with versions earlier than 9.1.1.172(C00E170R8P1) have an improper authentication vulnerability. A logic error occurs when handling clock function, an attacker should do a series of crafted operations quickly before the phone is unlocked, successful exploit could allow the attacker to access clock information without unlock the phone.

    Published: 29 May 2020
    3.3
    Low

    CVE-2020-3959

    Last Modified: 21 Nov 2024

    VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.1.0) and VMware Fusion (11.x before 11.1.0) contain a memory leak vulnerability in the VMCI module. A malicious actor with local non-administrative access to a virtual machine may be able to crash the virtual machine's vmx process leading to a partial denial of service.

    Published: 29 May 2020
    5.5
    Medium

    CVE-2020-3958

    Last Modified: 21 Nov 2024

    VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.5.2) and VMware Fusion (11.x before 11.5.2) contain a denial-of-service vulnerability in the shader functionality. Successful exploitation of this issue may allow attackers with non-administrative access to a virtual machine to crash the virtual machine's vmx process leading to a denial of service condition.

    Published: 29 May 2020
    7
    High

    CVE-2020-3957

    Last Modified: 21 Nov 2024

    VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC and Horizon Client are installed.

    Published: 29 May 2020
    4.6
    Medium

    CVE-2020-1809

    Last Modified: 21 Nov 2024

    HUAWEI Mate 10 smartphones with versions earlier than 10.0.0.143(C00E143R2P4) have an information disclosure vulnerability. The attacker could wake up voice assistant then do a series of crafted voice operation, successful exploit could allow the attacker read certain files without unlock the phone leading to information disclosure.

    Published: 29 May 2020
    2.4
    Low

    CVE-2020-1797

    Last Modified: 21 Nov 2024

    HUAWEI Mate 20 smartphones with versions earlier than 10.0.0.185(C00E74R3P8) have an improper authorization vulnerability. The system does not properly restrict certain operation in ADB mode, successful exploit could allow certain user break the limit of digital balance function.

    Published: 29 May 2020
    7.5
    High

    CVE-2020-1870

    Last Modified: 21 Nov 2024

    There is a denial of service vulnerability in some Huawei products. Due to improper memory management, memory leakage may occur in some special cases. Attackers can perform a series of operations to exploit this vulnerability. Successful exploit may cause a denial of service. Affected product versions include: CloudEngine 12800 versions V200R019C00SPC800; CloudEngine 5800 versions V200R019C00SPC800; CloudEngine 6800 versions V200R005C20SPC800, V200R019C00SPC800; CloudEngine 7800 versions V200R019C00SPC800; NE40E versions V800R011C00SPC200, V800R011C00SPC300, V800R011C10SPC100; NE40E-F versions V800R011C00SPC200, V800R011C10SPC100; NE40E-M versions V800R011C00SPC200, V800R011C10SPC100.

    Published: 29 May 2020
    8.8
    High

    CVE-2020-1832

    Last Modified: 21 Nov 2024

    E6878-370 products with versions of 10.0.3.1(H557SP27C233) and 10.0.3.1(H563SP1C00) have a stack buffer overflow vulnerability. The program copies an input buffer to an output buffer without verification. An attacker in the adjacent network could send a crafted message, successful exploit could lead to stack buffer overflow which may cause malicious code execution.

    Published: 29 May 2020
    4.6
    Medium

    CVE-2020-1798

    Last Modified: 21 Nov 2024

    HUAWEI P30 smartphones with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authentication vulnerability. A logic error occurs when handling NFC work, an attacker should establish a NFC connection to the target phone, and then do a series of operations on the target phone. Successful exploit could allow a guest user do certain operation which is beyond the guest user's privilege.

    Published: 29 May 2020
    7.2
    High

    CVE-2020-8816

    Last Modified: 10 Nov 2025

    Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

    Published: 29 May 2020
    10
    Critical

    CVE-2020-12493

    Last Modified: 21 Nov 2024

    An open port used for debugging in SWARCOs CPU LS4000 Series with versions starting with G4... grants root access to the device without access control via network. A malicious user could use this vulnerability to get access to the device and disturb operations with connected devices.

    Published: 29 May 2020
    7.8
    High

    CVE-2020-13634

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xF1002558

    Published: 29 May 2020
    8.8
    High

    CVE-2020-12675

    Last Modified: 21 Nov 2024

    The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related to creation/retrieval/deletion of PHP template files, leading to Remote Code Execution. NOTE: this issue exists because of an incomplete fix for CVE-2020-12077.

    Published: 29 May 2020
    6.1
    Medium

    CVE-2020-4490

    Last Modified: 21 Nov 2024

    IBM Business Automation Workflow 18 and 19, and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a vitcim to a phishing site. IBM X-Force ID: 181989

    Published: 29 May 2020
    7
    High

    CVE-2020-4352

    Last Modified: 21 Nov 2024

    IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when running in restricted mode. IBM X-Force ID: 178427.

    Published: 29 May 2020
    5.4
    Medium

    CVE-2020-4306

    Last Modified: 21 Nov 2024

    IBM Planning Analytics Local 2.0.0 through 2.0.9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176735.

    Published: 29 May 2020
    4.6
    Medium

    CVE-2020-5573

    Last Modified: 21 Nov 2024

    Android App 'kintone mobile for Android' 1.0.0 to 2.5 allows an attacker to obtain credential information registered in the product via unspecified vectors.

    Published: 29 May 2020
    4.6
    Medium

    CVE-2020-5572

    Last Modified: 21 Nov 2024

    Android App 'Mailwise for Android' 1.0.0 to 1.0.1 allows an attacker to obtain credential information registered in the product via unspecified vectors.

    Published: 29 May 2020