Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2020-05-22 CVE-2020-3184 SQL Injection vulnerability in Cisco Prime Collaboration Provisioning
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.
network
low complexity
cisco CWE-89
6.5
2020-05-22 CVE-2020-13384 Unrestricted Upload of File with Dangerous Type vulnerability in Monstra 3.0.4
Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, for example, .php filenames are blocked but .php7 filenames are not, a related issue to CVE-2017-18048.
network
low complexity
monstra CWE-434
6.5
2020-05-21 CVE-2020-12693 Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel.
network
high complexity
schedmd fedoraproject opensuse debian
8.1
2020-05-21 CVE-2020-1195 Improper Privilege Management vulnerability in Microsoft Edge
An elevation of privilege vulnerability exists in Microsoft Edge (Chromium-based) when the Feedback extension improperly validates input, aka 'Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability'.
network
microsoft CWE-269
4.3
2020-05-21 CVE-2020-1192 Unspecified vulnerability in Microsoft Visual Studio Code
A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads workspace settings from a notebook file, aka 'Visual Studio Code Python Extension Remote Code Execution Vulnerability'.
network
microsoft
critical
9.3
2020-05-21 CVE-2020-1191 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-05-21 CVE-2020-1190 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-05-21 CVE-2020-1189 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-05-21 CVE-2020-1188 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-05-21 CVE-2020-1187 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6