CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
7Debian DrupalFedoraproject+4 more52Active Iq Unified Manager Application ExpressApplication Testing Suite+49 moreJun 17, 2026 Apr 29, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(),...Show more |
2Fedoraproject Grafana2Fedora GrafanaJun 17, 2026 Apr 29, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable. |
3Fedoraproject GrafanaRedhat4Ceph Storage Enterprise LinuxFedora+1 moreJun 17, 2026 Apr 29, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive inform...Show more |
5Canonical DebianFedoraproject+2 more23A700s Firmware Active Iq Unified ManagerBootstrap Os+20 moreJun 17, 2026 Apr 29, 2020 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a...Show more |
5Apple DebianFedoraproject+2 more5Debian Linux FedoraJson+++2 moreJun 17, 2026 Apr 28, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on...Show more |
3Debian FedoraprojectOpenvpn3Debian Linux FedoraOpenvpnJun 17, 2026 Apr 27, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arrives before the data c...Show more |
3Debian FedoraprojectWisc3Debian Linux FedoraHtcondorJun 17, 2026 Apr 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If...Show more |
2Fedoraproject Trusteddomain2Fedora OpendmarcJun 17, 2026 Apr 27, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation...Show more |
3Fedoraproject Pypolicyd Spf ProjectTrusteddomain3Fedora OpendmarcPypolicyd SpfJun 17, 2026 Apr 27, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field. |
5Canonical DebianFedoraproject+2 more6Backports Sle Debian LinuxFedora+3 moreJun 17, 2026 Apr 24, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web...Show more |
5Canonical DebianFedoraproject+2 more6Ceph Ceph StorageDebian Linux+3 moreJun 17, 2026 Apr 23, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Apr 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow th...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Apr 22, 2020 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service. |
5Canonical DebianFedoraproject+2 more6Backports Sle Debian LinuxFedora+3 moreJun 17, 2026 Apr 22, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraGit+1 moreJun 17, 2026 Apr 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that b...Show more |
10Broadcom DebianFedoraproject+7 more26Active Iq Unified Manager Application ServerDebian Linux+23 moreJun 17, 2026 Apr 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert"...Show more |
2Fedoraproject Google2Android FedoraJun 17, 2026 Apr 17, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In finalize of AssetManager.java, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...Show more |
5Canonical FedoraprojectOpensuse+2 more5Fedora LeapUbuntu Linux+2 moreJun 17, 2026 Apr 17, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and app...Show more |
3Debian FedoraprojectOracle4Debian Linux FedoraMysql Connector/j+1 moreJun 17, 2026 Apr 15, 2020 N/A· v4 5.0 MEDIUM· v3 5.1 MEDIUM· v2 Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.19 and prior and 5.1.48 and prior. Difficult to exploit vulnerability allows unauthenti...Show more |
3Debian FedoraprojectOracle3Debian Linux FedoraMysql Connector/jJun 17, 2026 Apr 15, 2020 N/A· v4 2.2 LOW· v3 3.5 LOW· v2 Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 5.1.48 and prior. Difficult to exploit vulnerability allows high privileged attacker with n...Show more |