CVE Feed

    Dashboard / CVE

    4.9
    Medium

    CVE-2020-1995

    Last Modified: 21 Nov 2024

    A NULL pointer dereference vulnerability in Palo Alto Networks PAN-OS allows an authenticated administrator to send a request that causes the rasmgr daemon to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode. This issue affects: PAN-OS 9.1 versions earlier than 9.1.2.

    Published: 13 May 2020
    4.1
    Medium

    CVE-2020-1994

    Last Modified: 21 Nov 2024

    A predictable temporary file vulnerability in PAN-OS allows a local authenticated user with shell access to corrupt arbitrary system files affecting the integrity of the system. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.13; PAN-OS 9.0 versions earlier than 9.0.7.

    Published: 13 May 2020
    3.7
    Low

    CVE-2020-1993

    Last Modified: 21 Nov 2024

    The GlobalProtect Portal feature in PAN-OS does not set a new session identifier after a successful user login, which allows session fixation attacks, if an attacker is able to control a user's session ID. This issue affects: All PAN-OS 7.1 and 8.0 versions; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.8.

    Published: 13 May 2020
    7.9
    High

    CVE-2020-11073

    Last Modified: 21 Nov 2024

    In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could run arbitrary code without any user interaction. This is fixed in version: 1.16.0

    Published: 13 May 2020
    5.4
    Medium

    CVE-2020-11070

    Last Modified: 21 Nov 2024

    The SVG Sanitizer extension for TYPO3 has a cross-site scripting vulnerability in versions before 1.0.3. Slightly invalid or incomplete SVG markup is not correctly processed and thus not sanitized at all. Albeit the markup is not valid it still is evaluated in browsers and leads to cross-site scripting. This is fixed in version 1.0.3.

    Published: 13 May 2020
    9.8
    Critical

    CVE-2020-12832

    Last Modified: 21 Nov 2024

    WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.

    Published: 13 May 2020
    8.8
    High

    CVE-2020-5407

    Last Modified: 21 Nov 2024

    Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during SAML response validation. When using the spring-security-saml2-service-provider component, a malicious user can carefully modify an otherwise valid SAML response and append an arbitrary assertion that Spring Security will accept as valid.

    Published: 13 May 2020
    5.8
    Medium

    CVE-2019-2388

    Last Modified: 23 Feb 2026

    In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access log of a publicly exposed Ops Manager instance. This issue affects: MongoDB Inc. MongoDB Ops Manager 4.0 versions 4.0.9, 4.0.10 and MongoDB Ops Manager 4.1 version 4.1.5.

    Published: 13 May 2020
    4.8
    Medium

    CVE-2020-5838

    Last Modified: 21 Nov 2024

    Symantec IT Analytics, prior to 2.9.1, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can potentially enable attackers to inject client-side scripts into web pages viewed by other users.

    Published: 13 May 2020
    9.8
    Critical

    CVE-2019-15880

    Last Modified: 21 Nov 2024

    In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient checking in the cryptodev module allocated the size of a kernel buffer based on a user-supplied length allowing an unprivileged process to trigger a kernel panic.

    Published: 13 May 2020
    7.4
    High

    CVE-2019-15879

    Last Modified: 21 Nov 2024

    In FreeBSD 12.1-STABLE before r356908, 12.1-RELEASE before p5, 11.3-STABLE before r356908, and 11.3-RELEASE before p9, a race condition in the cryptodev module permitted a data structure in the kernel to be used after it was freed, allowing an unprivileged process can overwrite arbitrary kernel memory.

    Published: 13 May 2020
    7.8
    High

    CVE-2019-15878

    Last Modified: 21 Nov 2024

    In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local user can trigger a use-after-free situation due to improper checking in SCTP when an application tries to update an SCTP-AUTH shared key.

    Published: 13 May 2020
    5.5
    Medium

    CVE-2020-7455

    Last Modified: 21 Nov 2024

    In FreeBSD 12.1-STABLE before r360973, 12.1-RELEASE before p5, 11.4-STABLE before r360973, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, the FTP packet handler in libalias incorrectly calculates some packet length allowing disclosure of small amounts of kernel (for kernel NAT) or natd process space (for userspace natd).

    Published: 13 May 2020
    9.8
    Critical

    CVE-2020-7454

    Last Modified: 21 Nov 2024

    In FreeBSD 12.1-STABLE before r360971, 12.1-RELEASE before p5, 11.4-STABLE before r360971, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, libalias does not properly validate packet length resulting in modules causing an out of bounds read/write condition if no checking was built into the module.

    Published: 13 May 2020
    9.8
    Critical

    CVE-2020-9502

    Last Modified: 21 Nov 2024

    Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the device.

    Published: 13 May 2020
    5.5
    Medium

    CVE-2020-9501

    Last Modified: 21 Nov 2024

    Attackers can obtain Cloud Key information from the Dahua Web P2P control in specific ways. Cloud Key is used to authenticate the connection between the client tool and the platform. An attacker may use the leaked Cloud Key to impersonate the client to connect to the platform, resulting in additional consumption of platform server resources. Versions with Build time before April 2020 are affected.

    Published: 13 May 2020
    8.1
    High

    CVE-2019-9682

    Last Modified: 21 Nov 2024

    Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compatible with the normal login of early devices, some devices retain the weak security login mode that users can control. If the user uses a weak security login method, an attacker can monitor the device network to intercept network packets to attack the device. So it is recommended that the user disable this login method.

    Published: 13 May 2020
    6.5
    Medium

    CVE-2020-8020

    Last Modified: 21 Nov 2024

    A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attackers to store arbitrary JS code to cause XSS. This issue affects: openSUSE open-build-service versions prior to 7cc32c8e2ff7290698e101d9a80a9dc29a5500fb.

    Published: 13 May 2020
    8.8
    High

    CVE-2019-16112

    Last Modified: 21 Nov 2024

    TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java object to the recorder/ServiceManager?service=tyler.empire.settings.SettingManager URI.

    Published: 13 May 2020
    8.8
    High

    CVE-2020-12427

    Last Modified: 21 Nov 2024

    The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space.

    Published: 13 May 2020
    9.8
    Critical

    CVE-2020-12763

    Last Modified: 21 Nov 2024

    TRENDnet ProView Wireless camera TV-IP512WN 1.0R 1.0.4 is vulnerable to an unauthenticated stack-based buffer overflow in handling RTSP packets. This may result in remote code execution or denial of service. The issue is in the binary rtspd (in /sbin) when parsing a long "Authorization: Basic" RTSP header.

    Published: 13 May 2020
    6.1
    Medium

    CVE-2020-12742

    Last Modified: 21 Nov 2024

    The iubenda-cookie-law-solution plugin before 2.3.5 for WordPress does not restrict URL sanitization to http protocols.

    Published: 13 May 2020
    4.3
    Medium

    CVE-2020-12700

    Last Modified: 21 Nov 2024

    The direct_mail extension through 5.2.3 for TYPO3 allows Information Disclosure via a newsletter subscriber data Special Query.

    Published: 13 May 2020
    6.1
    Medium

    CVE-2020-12699

    Last Modified: 21 Nov 2024

    The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl.

    Published: 13 May 2020
    4.3
    Medium

    CVE-2020-12698

    Last Modified: 21 Nov 2024

    The direct_mail extension through 5.2.3 for TYPO3 has Broken Access Control for newsletter subscriber tables.

    Published: 13 May 2020
    5.3
    Medium

    CVE-2020-12697

    Last Modified: 21 Nov 2024

    The direct_mail extension through 5.2.3 for TYPO3 allows Denial of Service via log entries.

    Published: 13 May 2020
    9.8
    Critical

    CVE-2020-10654

    Last Modified: 21 Nov 2024

    Ping Identity PingID SSH before 4.0.14 contains a heap buffer overflow in PingID-enrolled servers. This condition can be potentially exploited into a Remote Code Execution vector on the authenticating endpoint.

    Published: 13 May 2020
    4.3
    Medium

    CVE-2020-4312

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0 trough 6.0.3.1 could allow an authenticated user to obtain sensitive information from a cached web page. IBM X-Force ID: 177089.

    Published: 13 May 2020
    7.5
    High

    CVE-2020-3341

    Last Modified: 21 Nov 2024

    A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a stack buffer overflow read. An attacker could exploit this vulnerability by sending a crafted PDF file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.

    Published: 13 May 2020
    7.5
    High

    CVE-2020-3327

    Last Modified: 21 Nov 2024

    A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a heap buffer overflow read. An attacker could exploit this vulnerability by sending a crafted ARJ file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.

    Published: 13 May 2020
    2.3
    Low

    CVE-2020-11932

    Last Modified: 21 Nov 2024

    It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one was entered.

    Published: 13 May 2020
    6
    Medium

    CVE-2020-10742

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel. An index buffer overflow during Direct IO write leading to the NFS client to crash. In some cases, a reach out of the index after one memory allocation by kmalloc will cause a kernel panic. The highest threat from this vulnerability is to data confidentiality and system availability.

    Published: 13 May 2020
    4.7
    Medium

    CVE-2020-1960

    Last Modified: 21 Nov 2024

    A vulnerability in Apache Flink (1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5.0 to 1.5.6, 1.6.0 to 1.6.4, 1.7.0 to 1.7.2, 1.8.0 to 1.8.3, 1.9.0 to 1.9.2, 1.10.0) where, when running a process with an enabled JMXReporter, with a port configured via metrics.reporter.reporter_name>.port, an attacker with local access to the machine and JMX port can execute a man-in-the-middle attack using a specially crafted request to rebind the JMXRMI registry to one under the attacker's control. This compromises any connection established to the process via JMX, allowing extraction of credentials and any other transferred data.

    Published: 13 May 2020
    7.5
    High

    CVE-2020-25708

    Last Modified: 21 Nov 2024

    A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, when processed by the VNC server, would lead to a floating point exception, resulting in a denial of service.

    Published: 13 May 2020
    6.3
    Medium

    CVE-2020-1945

    Last Modified: 21 Nov 2024

    Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.

    Published: 13 May 2020
    9.9
    Critical

    CVE-2020-11057

    Last Modified: 21 Nov 2024

    In XWiki Platform 7.2 through 11.10.2, registered users without scripting/programming permissions are able to execute python/groovy scripts while editing personal dashboards. This has been fixed 11.3.7 , 11.10.3 and 12.0.

    Published: 12 May 2020
    8.8
    High

    CVE-2020-12772

    Last Modified: 21 Nov 2024

    An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC attribute referencing an external host's IP address. Upon access to this external host, the (NT)LM hashes of the user are sent with the HTTP request. This allows an attacker to collect these hashes, crack them, and potentially compromise the computer. (ROAR can be configured for automatic access. Also, access can occur if the user clicks.)

    Published: 12 May 2020
    7.4
    High

    CVE-2020-11060

    Last Modified: 21 Nov 2024

    In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited by an attacker without a valid account by using a CSRF. Due to the difficulty of the exploitation, the attack is only conceivable by an account having Maintenance privileges and the right to add WIFI networks. This is fixed in version 9.4.6.

    Published: 12 May 2020
    6
    Medium

    CVE-2020-11062

    Last Modified: 21 Nov 2024

    In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type. This has been fixed in version 9.4.6.

    Published: 12 May 2020
    7.5
    High

    CVE-2020-10739

    Last Modified: 21 Nov 2024

    Istio 1.4.x before 1.4.9 and Istio 1.5.x before 1.5.4 contain the following vulnerability when telemetry v2 is enabled: by sending a specially crafted packet, an attacker could trigger a Null Pointer Exception resulting in a Denial of Service. This could be sent to the ingress gateway or a sidecar, triggering a null pointer exception which results in a denial of service. This also affects servicemesh-proxy where a null pointer exception flaw was found in servicemesh-proxy. When running Telemetry v2 (not on by default in version 1.4.x), an attacker could send a specially crafted packet to the ingress gateway or proxy sidecar, triggering a denial of service.

    Published: 12 May 2020
    9.8
    Critical

    CVE-2020-6242

    Last Modified: 21 Nov 2024

    SAP Business Objects Business Intelligence Platform (Live Data Connect), versions 1.0, 2.0, 2.1, 2.2, 2.3, allows an attacker to logon on the Central Management Console without password in case of the BIPRWS application server was not protected with some specific certificate, leading to Missing Authentication Check.

    Published: 12 May 2020
    6.5
    Medium

    CVE-2020-6258

    Last Modified: 21 Nov 2024

    SAP Identity Management, version 8.0, does not perform necessary authorization checks for an authenticated user, allowing the attacker to view certain sensitive information of the victim, leading to Missing Authorization Check.

    Published: 12 May 2020
    6.1
    Medium

    CVE-2020-6254

    Last Modified: 21 Nov 2024

    SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Site Scripting.

    Published: 12 May 2020
    8.8
    High

    CVE-2020-6241

    Last Modified: 21 Nov 2024

    SAP Adaptive Server Enterprise, version 16.0, allows an authenticated user to execute crafted database queries to elevate privileges of users in the system, leading to SQL Injection.

    Published: 12 May 2020
    6.5
    Medium

    CVE-2020-6259

    Last Modified: 21 Nov 2024

    Under certain conditions SAP Adaptive Server Enterprise, versions 15.7, 16.0, allows an attacker to access information which would otherwise be restricted leading to Missing Authorization Check.

    Published: 12 May 2020
    8
    High

    CVE-2020-6252

    Last Modified: 21 Nov 2024

    Under certain conditions SAP Adaptive Server Enterprise (Cockpit), version 16.0, allows an attacker with access to local network, to get sensitive and confidential information, leading to Information Disclosure. It can be used to get user account credentials, tamper with system data and impact system availability.

    Published: 12 May 2020
    7.2
    High

    CVE-2020-6253

    Last Modified: 21 Nov 2024

    Under certain conditions, SAP Adaptive Server Enterprise (Web Services), versions 15.7, 16.0, allows an authenticated user to execute crafted database queries to elevate their privileges, modify database objects, or execute commands they are not otherwise authorized to execute, leading to SQL Injection.

    Published: 12 May 2020
    7.8
    High

    CVE-2020-6244

    Last Modified: 27 May 2025

    SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious code as a DLL file in untrusted directories that can be executed by the application, due to uncontrolled search path element. An attacker could thereby control the behavior of the application.

    Published: 12 May 2020
    5.4
    Medium

    CVE-2020-6257

    Last Modified: 21 Nov 2024

    SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad) 4.2 does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability.

    Published: 12 May 2020
    6.8
    Medium

    CVE-2020-6250

    Last Modified: 21 Nov 2024

    SAP Adaptive Server Enterprise, version 16.0, allows an authenticated attacker to exploit certain misconfigured endpoints exposed over the adjacent network, to read system administrator password leading to Information Disclosure. This could help the attacker to read/write any data and even stop the server like an administrator.

    Published: 12 May 2020