LiveActive security incident?Get immediate response
CVE archive

May 2020

Browse CVE records published in May 2020, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1407 matching CVEs · Page 13 of 29.

Unknown · CVSS Not scored

CVE-2020-17514: disabled hostname verificiation

Apache Fineract prior to 1.5.0 disables HTTPS hostname verification in ProcessorHelper in the configureClient method. Under typical deployments, a man in the middle attack could be successful.

Published May 27, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-15522: Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA befo...

Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.

Published May 20, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-15180: A flaw was found in the mysql-wsrep component of mariadb.

A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera cluster nodes. This threatens the system's confidentiality, integrity, and availability. This flaw affects mariadb versions before 10.1.47, before 10.2.34, before 10.3.25, before 10.4.15 and before 10.5.6.

Published May 27, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-14387: A flaw was found in rsync in versions since 3.2.0pre1.

A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerability. A remote, unauthenticated attacker could exploit the flaw by performing a man-in-the-middle attack using a valid certificate for another hostname which could compromise confidentiality and integrity of data transmitted using rsync-ssl. The highest threat from this vulnerability is to data confidentiality and integrity. This flaw affects rsync versions before 3.2.4.

Published May 27, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-14328: A flaw was found in Ansible Tower in versions before 3.7.2.

A flaw was found in Ansible Tower in versions before 3.7.2. A Server Side Request Forgery flaw can be abused by supplying a URL which could lead to the server processing it connecting to internal services or exposing additional internal services and more particularly retrieving full details in case of error. The highest threat from this vulnerability is to data confidentiality.

Published May 27, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-14327: A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3....

A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is abused by supplying a URL that could lead to the server processing it. This flaw leads to the connection to internal services or the exposure of additional internal services by abusing the test feature of lookup credentials to forge HTTP/HTTPS requests from the server and retrieving the results of the response.

Published May 27, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-14329: A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can be expos...

A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can be exposed from the /api/v2/labels/ endpoint. This flaw allows users from other organizations in the system to retrieve any label from the organization and also disclose organization names. The highest threat from this vulnerability is to confidentiality.

Published May 27, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-14009: Proofpoint Enterprise Protection (PPS/PoD) before 8.16.4 contains a vulnerability that could allow an attac...

Proofpoint Enterprise Protection (PPS/PoD) before 8.16.4 contains a vulnerability that could allow an attacker to deliver an email message with a malicious attachment that bypasses scanning and file-blocking rules. The vulnerability exists because messages with certain crafted and malformed multipart structures are not properly handled.

Published May 7, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-13873: A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allo...

A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote attackers (pre-authentication) to bypass the admin page via a leaked password-reset token of the admin. (As an admin, an attacker can upload a PHP shell and execute remote code on the operating system.)

Published May 12, 2021 · Updated Aug 4, 2024

Medium · CVSS 5.4

CVE-2020-13644: An issue was discovered in the Accordion plugin before 2.2.9 for WordPress.

An issue was discovered in the Accordion plugin before 2.2.9 for WordPress. The unprotected AJAX wp_ajax_accordions_ajax_import_json action allowed any authenticated user with Subscriber or higher permissions the ability to import a new accordion and inject malicious JavaScript as part of the accordion.

Published May 28, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-13666: Cross-site scripting vulnerability in Drupal Core.

Cross-site scripting vulnerability in Drupal Core. Drupal AJAX API does not disable JSONP by default, allowing for an XSS attack. This issue affects: Drupal Drupal Core 7.x versions prior to 7.73; 8.8.x versions prior to 8.8.10; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.

Published May 5, 2021 · Updated Aug 4, 2024

High · CVSS 8.8

CVE-2020-13641: An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress.

An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The find and replace rules could be updated with malicious JavaScript, allowing for that be executed later in the victims browser.

Published May 28, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-13667: Access bypass vulnerability in of Drupal Core Workspaces allows an attacker to access data without correct...

Access bypass vulnerability in of Drupal Core Workspaces allows an attacker to access data without correct permissions. The Workspaces module doesn't sufficiently check access permissions when switching workspaces, leading to an access bypass vulnerability. An attacker might be able to see content before the site owner intends people to see the content. This vulnerability is mitigated by the fact that sites are only vulnerable if they have installed the experimental Workspaces module. This issue affects Drupal Core8.8.X versions prior to 8.8.10; 8.9.X versions prior to 8.9.6; 9.0.X versions prior to 9.0.6.

Published May 17, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-13627: Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via...

Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget.

Published May 27, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-13665: Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode.

Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the read_only set to FALSE under jsonapi.settings config are vulnerable. This issue affects: Drupal Drupal Core 8.8.x versions prior to 8.8.8; 8.9.x versions prior to 8.9.1; 9.0.x versions prior to 9.0.1.

Published May 5, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-13628: Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via...

Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to host-monitoring/src/toolbar.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget.

Published May 27, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-13664: Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances.

Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on the file system. With this directory in place, an attacker could attempt to brute force a remote code execution vulnerability. Windows servers are most likely to be affected. This issue affects: Drupal Drupal Core 8.8.x versions prior to 8.8.8; 8.9.x versions prior to 8.9.1; 9.0.1 versions prior to 9.0.1.

Published May 5, 2021 · Updated Aug 4, 2024