CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2020-4411

    Last Modified: 21 Nov 2024

    The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of service vulnerability in its kernel module that could allow an attacker to cause a denial of service condition on the affected system. To exploit this vulnerability, a local attacker could invoke a subset of ioctls on the Spectrum Scale device with non-valid arguments. This could allow the attacker to crash the kernel. IBM X-Force ID: 179986.

    Published: 19 May 2020
    5.4
    Medium

    CVE-2020-4298

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176475.

    Published: 19 May 2020
    6.5
    Medium

    CVE-2020-4286

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 176268.

    Published: 19 May 2020
    6.1
    Medium

    CVE-2020-6956

    Last Modified: 21 Nov 2024

    PCS DEXICON 3.4.1 allows XSS via the loginName parameter in login_action.jsp.

    Published: 19 May 2020
    9.8
    Critical

    CVE-2020-8434

    Last Modified: 21 Nov 2024

    Jenzabar JICS (aka Internet Campus Solution) before 9.0.1 Patch 3, 9.1 before 9.1.2 Patch 2, and 9.2 before 9.2.2 Patch 8 has session cookies that are a deterministic function of the username. There is a hard-coded password to supply a PBKDF feeding into AES to encrypt a username and base64 encode it to a client-side cookie for persistent session authentication. By knowing the key and algorithm, an attacker can select any username, encrypt it, base64 encode it, and save it in their browser with the correct JICSLoginCookie cookie format to impersonate any real user in the JICS database without the need for authenticating (or verifying with MFA if implemented).

    Published: 19 May 2020
    8.1
    High

    CVE-2020-14062

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).

    Published: 19 May 2020
    8.1
    High

    CVE-2020-14061

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and oracle.jms.AQjmsXAConnectionFactory (aka weblogic/oracle-aqjms).

    Published: 19 May 2020
    8.1
    High

    CVE-2020-14060

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).

    Published: 19 May 2020
    7.5
    High

    CVE-2020-12662

    Last Modified: 21 Nov 2024

    Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.

    Published: 19 May 2020
    7.5
    High

    CVE-2020-12663

    Last Modified: 21 Nov 2024

    Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.

    Published: 19 May 2020
    9.6
    Critical

    CVE-2020-6466

    Last Modified: 21 Nov 2024

    Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 19 May 2020
    8.8
    High

    CVE-2020-6467

    Last Modified: 21 Nov 2024

    Use after free in WebRTC in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 19 May 2020
    9.6
    Critical

    CVE-2020-6471

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

    Published: 19 May 2020
    6.5
    Medium

    CVE-2020-6472

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory or disk via a crafted Chrome Extension.

    Published: 19 May 2020
    6.5
    Medium

    CVE-2020-6475

    Last Modified: 21 Nov 2024

    Incorrect implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.

    Published: 19 May 2020
    6.5
    Medium

    CVE-2020-6478

    Last Modified: 21 Nov 2024

    Inappropriate implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.

    Published: 19 May 2020
    6.5
    Medium

    CVE-2020-6484

    Last Modified: 21 Nov 2024

    Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted request.

    Published: 19 May 2020
    4.3
    Medium

    CVE-2020-6490

    Last Modified: 21 Nov 2024

    Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page.

    Published: 19 May 2020
    6.1
    Medium

    CVE-2020-7656

    Last Modified: 21 Nov 2024

    jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.

    Published: 19 May 2020
    8.6
    High

    CVE-2020-8616

    Last Modified: 21 Nov 2024

    A malicious actor who intentionally exploits this lack of effective limitation on the number of fetches performed when processing referrals can, through the use of specially crafted referrals, cause a recursing server to issue a very large number of fetches in an attempt to process the referral. This has at least two potential effects: The performance of the recursing server can potentially be degraded by the additional work required to perform these fetches, and The attacker can exploit this behavior to use the recursing server as a reflector in a reflection attack with a high amplification factor.

    Published: 19 May 2020
    7.5
    High

    CVE-2020-8617

    Last Modified: 21 Nov 2024

    Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local session key even on servers whose configuration does not otherwise make use of it, almost all current BIND servers are vulnerable. In releases of BIND dating from March 2018 and after, an assertion check in tsig.c detects this inconsistent state and deliberately exits. Prior to the introduction of the check the server would continue operating in an inconsistent state, with potentially harmful results.

    Published: 19 May 2020
    7.5
    High

    CVE-2020-12667

    Last Modified: 21 Nov 2024

    Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.

    Published: 19 May 2020
    9.6
    Critical

    CVE-2020-6465

    Last Modified: 21 Nov 2024

    Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 19 May 2020
    8.8
    High

    CVE-2020-6468

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 19 May 2020
    9.6
    Critical

    CVE-2020-6469

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

    Published: 19 May 2020
    6.1
    Medium

    CVE-2020-6470

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in clipboard in Google Chrome prior to 83.0.4103.61 allowed a local attacker to inject arbitrary scripts or HTML (UXSS) via crafted clipboard contents.

    Published: 19 May 2020
    6.5
    Medium

    CVE-2020-6473

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 19 May 2020
    8.8
    High

    CVE-2020-6474

    Last Modified: 21 Nov 2024

    Use after free in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 19 May 2020
    6.5
    Medium

    CVE-2020-6476

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in tab strip in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

    Published: 19 May 2020
    6.5
    Medium

    CVE-2020-6479

    Last Modified: 21 Nov 2024

    Inappropriate implementation in sharing in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.

    Published: 19 May 2020
    6.5
    Medium

    CVE-2020-6480

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in enterprise in Google Chrome prior to 83.0.4103.61 allowed a local attacker to bypass navigation restrictions via UI actions.

    Published: 19 May 2020
    6.5
    Medium

    CVE-2020-6481

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in URL formatting in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to perform domain spoofing via a crafted domain name.

    Published: 19 May 2020
    6.5
    Medium

    CVE-2020-6482

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

    Published: 19 May 2020
    6.5
    Medium

    CVE-2020-6485

    Last Modified: 21 Nov 2024

    Insufficient data validation in media router in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.

    Published: 19 May 2020
    6.5
    Medium

    CVE-2020-6486

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in navigations in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 19 May 2020
    6.5
    Medium

    CVE-2020-6487

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 19 May 2020
    4.3
    Medium

    CVE-2020-6488

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 19 May 2020
    7.8
    High

    CVE-2020-6477

    Last Modified: 21 Nov 2024

    Inappropriate implementation in installer in Google Chrome on OS X prior to 83.0.4103.61 allowed a local attacker to perform privilege escalation via a crafted file.

    Published: 19 May 2020
    6.5
    Medium

    CVE-2020-6483

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in payments in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 19 May 2020
    4.3
    Medium

    CVE-2020-6489

    Last Modified: 21 Nov 2024

    Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had convinced the user to take certain actions in developer tools to obtain potentially sensitive information from disk via a crafted HTML page.

    Published: 19 May 2020
    6.5
    Medium

    CVE-2020-6491

    Last Modified: 21 Nov 2024

    Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted domain name.

    Published: 19 May 2020
    5.4
    Medium

    CVE-2020-7676

    Last Modified: 20 Nov 2025

    angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping "<option>" elements in "<select>" ones changes parsing behavior, leading to possibly unsanitizing code.

    Published: 19 May 2020
    7.8
    High

    CVE-2019-17066

    Last Modified: 21 Nov 2024

    In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry hives (HKCU) when starting an application with elevated rights.

    Published: 18 May 2020
    6.5
    Medium

    CVE-2020-13154

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.

    Published: 18 May 2020
    9.8
    Critical

    CVE-2020-1897

    Last Modified: 21 Nov 2024

    A use-after-free is possible due to an error in lifetime management in the request adaptor when a malicious client invokes request error handling in a specific sequence. This issue affects versions of proxygen prior to v2020.05.18.00.

    Published: 18 May 2020
    6.1
    Medium

    CVE-2020-13153

    Last Modified: 21 Nov 2024

    app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view.

    Published: 18 May 2020
    5.4
    Medium

    CVE-2020-13094

    Last Modified: 21 Nov 2024

    Dolibarr before 11.0.4 allows XSS.

    Published: 18 May 2020
    7.8
    High

    CVE-2020-13149

    Last Modified: 21 Nov 2024

    Weak permissions on the "%PROGRAMDATA%\MSI\Dragon Center" folder in Dragon Center before 2.6.2003.2401, shipped with Micro-Star MSI Gaming laptops, allows local authenticated users to overwrite system files and gain escalated privileges. One attack method is to change the Recommended App binary within App.json. Another attack method is to use this part of %PROGRAMDATA% for mounting an RPC Control directory.

    Published: 18 May 2020
    5.4
    Medium

    CVE-2020-13145

    Last Modified: 21 Nov 2024

    Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS.

    Published: 18 May 2020
    8.8
    High

    CVE-2020-13146

    Last Modified: 21 Nov 2024

    Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profile info" feature.

    Published: 18 May 2020