LiveActive security incident?Get immediate response
CVE archive

June 2020

Browse CVE records published in June 2020, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1976 matching CVEs · Page 14 of 40.

Unknown · CVSS Not scored

CVE-2020-15412: An issue was discovered in MISP 2.4.128.

An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding to allow a user to send an event contact form.

Published Jun 30, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-15397: HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable...

HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileged users (e.g., locations under /var/spool/hylafax that are writable by the uucp account). This allows these users to execute code in the context of the user calling these binaries (often root).

Published Jun 30, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-15308: Support Incident Tracker (aka SiT!

Support Incident Tracker (aka SiT! or SiTracker) 3.67 p2 allows post-authentication SQL injection via the site_edit.php typeid or site parameter, the search_incidents_advanced.php search_title parameter, or the report_qbe.php criteriafield parameter.

Published Jun 26, 2020 · Updated Aug 4, 2024