CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2020-10754

    Last Modified: 21 Nov 2024

    It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and the connection is made insecurely.

    Published: 29 May 2020
    3.1
    Low

    CVE-2020-11086

    Last Modified: 21 Nov 2024

    In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_ntlm_v2_client_challenge that reads up to 28 bytes out-of-bound to an internal structure. This has been fixed in 2.1.0.

    Published: 29 May 2020
    2.6
    Low

    CVE-2020-11085

    Last Modified: 21 Nov 2024

    In FreeRDP before 2.1.0, there is an out-of-bounds read in cliprdr_read_format_list. Clipboard format data read (by client or server) might read data out-of-bounds. This has been fixed in 2.1.0.

    Published: 29 May 2020
    3.1
    Low

    CVE-2020-11087

    Last Modified: 21 Nov 2024

    In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_AuthenticateMessage. This has been fixed in 2.1.0.

    Published: 29 May 2020
    3.1
    Low

    CVE-2020-11088

    Last Modified: 21 Nov 2024

    In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_NegotiateMessage. This has been fixed in 2.1.0.

    Published: 29 May 2020
    3.7
    Low

    CVE-2020-11089

    Last Modified: 21 Nov 2024

    In FreeRDP before 2.1.0, there is an out-of-bound read in irp functions (parallel_process_irp_create, serial_process_irp_create, drive_process_irp_write, printer_process_irp_write, rdpei_recv_pdu, serial_process_irp_write). This has been fixed in 2.1.0.

    Published: 29 May 2020
    9.8
    Critical

    CVE-2022-29599

    Last Modified: 21 Nov 2024

    In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.

    Published: 29 May 2020
    9.8
    Critical

    CVE-2020-13693

    Last Modified: 21 Nov 2024

    An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.

    Published: 28 May 2020
    6.4
    Medium

    CVE-2020-11082

    Last Modified: 21 Nov 2024

    In Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1.

    Published: 28 May 2020
    7.8
    High

    CVE-2020-13173

    Last Modified: 21 Nov 2024

    Initialization of the pcoip_credential_provider in Teradici PCoIP Standard Agent for Windows and PCoIP Graphics Agent for Windows versions 19.11.1 and earlier creates an insecure named pipe, which allows an attacker to intercept sensitive information or possibly elevate privileges via pre-installing an application which acquires that named pipe.

    Published: 28 May 2020
    9.8
    Critical

    CVE-2019-6342

    Last Modified: 21 Nov 2024

    An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.

    Published: 28 May 2020
    7.1
    High

    CVE-2020-5357

    Last Modified: 21 Nov 2024

    Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File Overwrite vulnerability. The vulnerability is limited to the Dell Dock Firmware Update Utilities during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged malicious user could exploit this vulnerability by tricking an administrator into overwriting arbitrary files via a symlink attack. The vulnerability does not affect the actual binary payload that the update utility delivers.

    Published: 28 May 2020
    4.8
    Medium

    CVE-2020-13660

    Last Modified: 21 Nov 2024

    CMS Made Simple through 2.2.14 allows XSS via a crafted File Picker profile name.

    Published: 28 May 2020
    8.6
    High

    CVE-2020-11079

    Last Modified: 21 Nov 2024

    node-dns-sync (npm module dns-sync) through 0.2.0 allows execution of arbitrary commands . This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This has been fixed in 0.2.1.

    Published: 28 May 2020
    5.9
    Medium

    CVE-2020-13245

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10, and possibly R6120, R7800, R6220, R8000, R6350, R9000, R6400, RAX120, R6400v2, RBR20, R6800, XR300, R6850, XR500, and R7000P.

    Published: 28 May 2020
    5.3
    Medium

    CVE-2020-8330

    Last Modified: 21 Nov 2024

    A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggered by a remote user sending a crafted packet to the device, preventing subsequent print jobs until the printer is rebooted.

    Published: 28 May 2020
    5.3
    Medium

    CVE-2020-8329

    Last Modified: 21 Nov 2024

    A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggered by a remote user sending a crafted packet to the device, causing an error to be displayed and preventing printer from functioning until the printer is rebooted.

    Published: 28 May 2020
    2.7
    Low

    CVE-2020-4248

    Last Modified: 21 Nov 2024

    IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 175484.

    Published: 28 May 2020
    5.4
    Medium

    CVE-2020-4419

    Last Modified: 21 Nov 2024

    IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 180071.

    Published: 28 May 2020
    6.5
    Medium

    CVE-2020-4249

    Last Modified: 21 Nov 2024

    IBM Security Identity Governance and Intelligence 5.2.6 could disclose highly sensitive information to other authenticated users on the sytem due to incorrect authorization. IBM X-Force ID: 175485.

    Published: 28 May 2020
    7.1
    High

    CVE-2020-4246

    Last Modified: 21 Nov 2024

    IBM Security Identity Governance and Intelligence 5.2.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 175481.

    Published: 28 May 2020
    7.5
    High

    CVE-2020-4245

    Last Modified: 21 Nov 2024

    IBM Security Identity Governance and Intelligence 5.2.6 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 175423.

    Published: 28 May 2020
    5.3
    Medium

    CVE-2020-4244

    Last Modified: 21 Nov 2024

    IBM Security Identity Governance and Intelligence 5.2.6 could allow an unauthorized user to obtain sensitive information through user enumeration. IBM X-Force ID: 175422.

    Published: 28 May 2020
    5.3
    Medium

    CVE-2020-4233

    Last Modified: 21 Nov 2024

    IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information. IBM X-Force ID: 175360.

    Published: 28 May 2020
    7.5
    High

    CVE-2020-4232

    Last Modified: 21 Nov 2024

    IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to enumerate usernames to find valid login credentials which could be used to attempt further attacks against the system. IBM X-Force ID: 175336.

    Published: 28 May 2020
    6.5
    Medium

    CVE-2020-4231

    Last Modified: 21 Nov 2024

    IBM Security Identity Governance and Intelligence 5.2.6 could allow an authenticated user to perform unauthorized commands due to hazardous input validation. IBM X-Force ID: 175335.

    Published: 28 May 2020
    7.5
    High

    CVE-2020-13649

    Last Modified: 21 Nov 2024

    parser/js/js-scanner.c in JerryScript 2.2.0 mishandles errors during certain out-of-memory conditions, as demonstrated by a scanner_reverse_info_list NULL pointer dereference and a scanner_scan_all assertion failure.

    Published: 28 May 2020
    7.8
    High

    CVE-2020-7812

    Last Modified: 21 Nov 2024

    Ezhttptrans.ocx ActiveX Control in Kaoni ezHTTPTrans 1.0.0.70 and prior versions contain a vulnerability that could allow remote attacker to download arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution by rebooting the victim’s PC.

    Published: 28 May 2020
    8.8
    High

    CVE-2020-11950

    Last Modified: 21 Nov 2024

    VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execute a script (with resultant execution of OS commands). For example, this affects IT9388-HT devices.

    Published: 28 May 2020
    6.5
    Medium

    CVE-2020-11949

    Last Modified: 21 Nov 2024

    testserver.cgi of the web service on VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to obtain arbitrary files from a camera's local filesystem. For example, this affects IT9388-HT devices.

    Published: 28 May 2020
    8.8
    High

    CVE-2020-13642

    Last Modified: 21 Nov 2024

    An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The panels_data $_POST variable allows for malicious JavaScript to be executed in the victim's browser.

    Published: 28 May 2020
    8.8
    High

    CVE-2020-13643

    Last Modified: 21 Nov 2024

    An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The live_editor_panels_data $_POST variable allows for malicious JavaScript to be executed in the victim's browser.

    Published: 28 May 2020
    5.4
    Medium

    CVE-2020-13644

    Last Modified: 21 Nov 2024

    An issue was discovered in the Accordion plugin before 2.2.9 for WordPress. The unprotected AJAX wp_ajax_accordions_ajax_import_json action allowed any authenticated user with Subscriber or higher permissions the ability to import a new accordion and inject malicious JavaScript as part of the accordion.

    Published: 28 May 2020
    8.8
    High

    CVE-2020-13641

    Last Modified: 21 Nov 2024

    An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The find and replace rules could be updated with malicious JavaScript, allowing for that be executed later in the victims browser.

    Published: 28 May 2020
    9.8
    Critical

    CVE-2020-8606

    Last Modified: 21 Nov 2024

    A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected installations of Trend Micro InterScan Web Security Virtual Appliance.

    Published: 27 May 2020
    7.5
    High

    CVE-2020-8604

    Last Modified: 21 Nov 2024

    A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations.

    Published: 27 May 2020
    8.8
    High

    CVE-2020-8605

    Last Modified: 21 Nov 2024

    A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected installations. Authentication is required to exploit this vulnerability.

    Published: 27 May 2020
    6.1
    Medium

    CVE-2020-8603

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability (XSS) in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow a remote attacker to tamper with the web interface of affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

    Published: 27 May 2020
    7.7
    High

    CVE-2020-11075

    Last Modified: 21 Nov 2024

    In Anchore Engine version 0.7.0, a specially crafted container image manifest, fetched from a registry, can be used to trigger a shell escape flaw in the anchore engine analyzer service during an image analysis process. The image analysis operation can only be executed by an authenticated user via a valid API request to anchore engine, or if an already added image that anchore is monitoring has its manifest altered to exploit the same flaw. A successful attack can be used to execute commands that run in the analyzer environment, with the same permissions as the user that anchore engine is run as - including access to the credentials that Engine uses to access its own database which have read-write ability, as well as access to the running engien analyzer service environment. By default Anchore Engine is released and deployed as a container where the user is non-root, but if users run Engine directly or explicitly set the user to 'root' then that level of access may be gained in the execution environment where Engine runs. This issue is fixed in version 0.7.1.

    Published: 27 May 2020
    9.6
    Critical

    CVE-2020-11059

    Last Modified: 21 Nov 2024

    In AEgir greater than or equal to 21.7.0 and less than 21.10.1, aegir publish and aegir build may leak secrets from environment variables in the browser bundle published to npm. This has been fixed in 21.10.1.

    Published: 27 May 2020
    7.8
    High

    CVE-2020-10936

    Last Modified: 21 Nov 2024

    Sympa before 6.2.56 allows privilege escalation.

    Published: 27 May 2020
    9.3
    Critical

    CVE-2020-6774

    Last Modified: 21 Nov 2024

    Improper Access Control in the Kiosk Mode functionality of Bosch Recording Station allows a local unauthenticated attacker to escape from the Kiosk Mode and access the underlying operating system.

    Published: 27 May 2020
    6.1
    Medium

    CVE-2020-13628

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to host-monitoring/src/toolbar.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget.

    Published: 27 May 2020
    6.1
    Medium

    CVE-2020-13627

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget.

    Published: 27 May 2020
    6.1
    Medium

    CVE-2020-10946

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the page parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget.

    Published: 27 May 2020
    4.3
    Medium

    CVE-2020-10945

    Last Modified: 21 Nov 2024

    Centreon before 19.10.7 exposes Session IDs in server responses.

    Published: 27 May 2020
    6.1
    Medium

    CVE-2020-13633

    Last Modified: 21 Nov 2024

    Fork before 5.8.3 allows XSS via navigation_title or title.

    Published: 27 May 2020
    7.5
    High

    CVE-2020-4379

    Last Modified: 21 Nov 2024

    IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 179158.

    Published: 27 May 2020
    4.9
    Medium

    CVE-2020-4378

    Last Modified: 21 Nov 2024

    IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a privileged authenticated user to perform unauthorized actions using a specially crated HTTP POST command. IBM X-Force ID: 179157.

    Published: 27 May 2020
    5.4
    Medium

    CVE-2020-4358

    Last Modified: 21 Nov 2024

    IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178762.

    Published: 27 May 2020