CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian OpensuseRoundcube4Backports Sle Debian LinuxLeap+1 moreJun 17, 2026 May 4, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Apr 30, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ability to add conte...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Apr 30, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scripting (XSS) attacks. This has been patched in version 5.4.1, along with all...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Apr 30, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.1, along with all the...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Apr 30, 2020 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful exec...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Apr 30, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to uploa...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Apr 30, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patc...Show more |
4Canonical DebianGnu+1 more8Active Iq Unified Manager Debian LinuxGlibc+5 moreJun 17, 2026 Apr 30, 2020 N/A· v4 7.0 HIGH· v3 3.7 LOW· v2 A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by...Show more |
6Blackberry CanonicalDebian+3 more6Application Remote Collector Debian LinuxLeap+3 moreJun 17, 2026 Apr 30, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary direc...Show more |
5Canonical DebianOpensuse+2 more5Application Remote Collector Debian LinuxLeap+2 moreJun 17, 2026 Apr 30, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without...Show more |
8Debian DrupalFedoraproject+5 more70Agile Product Lifecycle Management For Process Agile Product Supplier Collaboration For ProcessApplication Testing Suite+67 moreJun 17, 2026 Apr 29, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted co...Show more |
7Debian DrupalFedoraproject+4 more52Active Iq Unified Manager Application ExpressApplication Testing Suite+49 moreJun 17, 2026 Apr 29, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(),...Show more |
5Canonical DebianFedoraproject+2 more23A700s Firmware Active Iq Unified ManagerBootstrap Os+20 moreJun 17, 2026 Apr 29, 2020 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a...Show more |
5Apple DebianFedoraproject+2 more5Debian Linux FedoraJson+++2 moreJun 17, 2026 Apr 28, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on...Show more |
8Apple BroadcomCanonical+5 more18Brocade Fabric Operating System Cloud BackupDebian Linux+15 moreJun 17, 2026 Apr 28, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash). |
2Debian Otrs2Debian Linux OtrsJun 17, 2026 Apr 28, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore it's possible to mix them and to send private key to the third-party instead of public key. This iss...Show more |
3Canonical DebianFfmpeg3Debian Linux FfmpegUbuntu LinuxJun 17, 2026 Apr 28, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MARKER_SOS handling because of a missing length check. |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Apr 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack. |
4Debian OraclePhp+1 more4Communications Diameter Signaling Router Debian LinuxPhp+1 moreJun 17, 2026 Apr 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erro...Show more |
2Debian Libgit22Debian Linux Libgit2Jun 17, 2026 Apr 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository....Show more |