LiveActive security incident?Get immediate response
CVE archive

August 2020

Browse CVE records published in August 2020, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1515 matching CVEs · Page 16 of 31.

Unknown · CVSS Not scored

CVE-2020-18469: Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page u...

Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Configuration menu in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to /rukovoditel_2.4.1/index.php?module=configuration/save&redirect_to=configuration/application.

Published Aug 26, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-17489: An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4.

An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time, it is then visible for a brief moment upon a logout. (If the password were never shown in cleartext, only the password length is revealed.)

Published Aug 11, 2020 · Updated Aug 4, 2024

Medium · CVSS 6

CVE-2020-17401: This vulnerability allows local attackers to disclose sensitive informations on affected installations of P...

This vulnerability allows local attackers to disclose sensitive informations on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the VGA virtual device. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated array. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute code in the context of the hypervisor. Was ZDI-CAN-11363.

Published Aug 25, 2020 · Updated Aug 4, 2024