Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2020-06-03 CVE-2020-3203 Memory Leak vulnerability in Cisco IOS XE
A vulnerability in the locally significant certificate (LSC) provisioning feature of Cisco Catalyst 9800 Series Wireless Controllers that are running Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak that could lead to a denial of service (DoS) condition.
network
low complexity
cisco CWE-401
7.8
2020-06-03 CVE-2020-3199 Unspecified vulnerability in Cisco IOS
Multiple vulnerabilities in the Cisco IOx application environment of Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) that are running Cisco IOS Software could allow an attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.
low complexity
cisco
8.3
2020-06-03 CVE-2020-4177 Use of Hard-coded Credentials vulnerability in IBM Security Guardium 11.1
IBM Security Guardium 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
network
low complexity
ibm CWE-798
7.5
2020-06-03 CVE-2020-13756 Improper Input Validation vulnerability in Sabberworm PHP CSS Parser
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker.
network
low complexity
sabberworm CWE-20
7.5
2020-06-03 CVE-2020-10516 Files or Directories Accessible to External Parties vulnerability in Github
An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissions and gain access to unauthorized repositories within an organization.
network
low complexity
github CWE-552
7.5
2020-06-03 CVE-2020-2200 OS Command Injection vulnerability in Jenkins Play Framework
Jenkins Play Framework Plugin 1.0.2 and earlier lets users specify the path to the `play` command on the Jenkins master for a form validation endpoint, resulting in an OS command injection vulnerability exploitable by users able to store such a file on the Jenkins master.
network
low complexity
jenkins CWE-78
8.8
2020-06-03 CVE-2020-2196 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Selenium
Jenkins Selenium Plugin 3.141.59 and earlier has no CSRF protection for its HTTP endpoints, allowing attackers to perform all administrative actions provided by the plugin.
network
low complexity
jenkins CWE-352
8.0
2020-06-02 CVE-2020-7663 websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. 7.5
2020-06-02 CVE-2020-3645 Reachable Assertion vulnerability in Qualcomm products
Firmware will hit assert in WLAN firmware If encrypted data length in FILS IE of reassoc response is more than 528 bytes in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ6018, IPQ8074, Kamorta, Nicobar, QCA6390, QCA8081, QCN7605, QCS404, QCS405, QCS605, Rennell, SC7180, SC8180X, SDA845, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SXR1130, SXR2130
network
low complexity
qualcomm CWE-617
7.8
2020-06-02 CVE-2020-3625 Classic Buffer Overflow vulnerability in Qualcomm Sm8250 Firmware and Sxr2130 Firmware
When making query to DSP capabilities, Stack out of bounds occurs due to wrong buffer length configured for DSP attributes in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile in SM8250, SXR2130
local
low complexity
qualcomm CWE-120
7.2