CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jun 12, 2020 N/A· v4 6.8 MEDIUM· v3 3.5 LOW· v2 In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the...Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jun 12, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts are viewed by a hig...Show more |
5Canonical DebianFedoraproject+2 more5Android Debian LinuxFedora+2 moreJun 17, 2026 Jun 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is n...Show more |
3Fedoraproject GoogleLibexif Project3Android FedoraLibexifJun 17, 2026 Jun 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interact...Show more |
2Fedoraproject Katacontainers2Fedora RuntimeJun 17, 2026 Jun 10, 2020 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path...Show more |
2Fedoraproject Nagios2Fedora NagiosJun 17, 2026 Jun 9, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, o...Show more |
7Canonical DebianFedoraproject+4 more10Active Iq Unified Manager Cloud BackupDebian Linux+7 moreJun 17, 2026 Jun 9, 2020 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system. |
3Debian FedoraprojectRoundcube3Debian Linux FedoraWebmailJun 17, 2026 Jun 9, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview. |
3Debian FedoraprojectRoundcube3Debian Linux FedoraWebmailJun 17, 2026 Jun 9, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object. |
4Fedoraproject MumbleOpensuse+1 more4Fedora LeapMumble+1 moreJun 17, 2026 Jun 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS s...Show more |
2Fedoraproject Gnome2Fedora NetworkmanagerJun 17, 2026 Jun 8, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the...Show more |
5Canonical DebianFedoraproject+2 more6Backports Sle Debian LinuxFedora+3 moreJun 17, 2026 Jun 8, 2020 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. T...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPhpmailer+1 moreJun 17, 2026 Jun 8, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay process...Show more |
21Asus BroadcomCanon+18 more2175020 Z4a69a 5030 M2u92b5030 Z4a70a+214 moreJun 17, 2026 Jun 8, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscriptio...Show more |
3Fedoraproject LibreofficeOpensuse3Fedora LeapLibreofficeJun 17, 2026 Jun 8, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements...Show more |
3Fedoraproject LibreofficeOpensuse3Fedora LeapLibreofficeJun 17, 2026 Jun 8, 2020 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreO...Show more |
6Debian FedoraprojectNetapp+3 more12Cloud Backup Communications Messaging ServerCommunications Network Charging And Control+9 moreJun 17, 2026 Jun 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late. |
2Fedoraproject Targetcli Fb Project2Fedora Targetcli FbJun 17, 2026 Jun 5, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files). |
2Fedoraproject Kubernetes2Fedora KubernetesJun 17, 2026 Jun 5, 2020 N/A· v4 6.3 MEDIUM· v3 3.5 LOW· v2 The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users...Show more |
5Fedoraproject NetappOpensuse+2 more16Communications Billing And Revenue Management Communications Diameter Signaling RouterCommunications Eagle Application Processor+13 moreJun 17, 2026 Jun 5, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls. |