|
198791
|
7.4 |
HIGH
Network
|
jetbrains
|
intellij_idea
|
In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-7904
|
2024-11-21 14:37 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198792
|
7.2 |
HIGH
Network
|
fusionauth
|
fusionauth
|
An issue was discovered in FusionAuth before 1.11.0. An authenticated user, allowed to edit e-mail templates (Home -> Settings -> Email Templates) or themes (Home -> Settings -> Themes), can execute …
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2020-7799
|
2024-11-21 14:37 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198793
|
8.8 |
HIGH
Network
|
codecov
|
nodejs_uploader
|
Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.
|
CWE-78
OS Command
|
CVE-2020-7596
|
2024-11-21 14:37 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198794
|
7.5 |
HIGH
Network
|
xmlsoft fedoraproject canonical debian siemens netapp oracle
|
libxml2 fedora ubuntu_linux debian_linux sinema_remote_connect_server steelstore_cloud_integrated_storage clustered_data_ontap smi-s_provider snapdrive symantec_netbackup
|
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-7595
|
2024-11-21 14:37 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198795
|
7.2 |
HIGH
Network
|
multitech
|
conduit_mtcdt-lvw2-246a_firmware
|
MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Debug Options page and entering shell metac…
|
CWE-78
OS Command
|
CVE-2020-7594
|
2024-11-21 14:37 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198796
|
4.8 |
MEDIUM
Network
|
sonoff
|
th10_firmware th16_firmware
|
Sonoff TH 10 and 16 devices with firmware 6.6.0.21 allows XSS via the Friendly Name 1 field (after a successful login with the Web Admin Password).
|
CWE-79
Cross-site Scripting
|
CVE-2020-7470
|
2024-11-21 14:37 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198797
|
7.5 |
HIGH
Network
|
mozilla
|
bleach
|
bleach.clean behavior parsing style attributes could result in a regular expression denial of service (ReDoS). Calls to bleach.clean with an allowed tag with an allowed style attribute are vulnerable…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2020-6817
|
2024-11-21 14:36 |
2023-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198798
|
9.8 |
CRITICAL
Network
|
seagate
|
stcg2000300_firmware stcg3000300_firmware stcg4000300_firmware
|
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_help…
|
CWE-78
OS Command
|
CVE-2020-6627
|
2024-11-21 14:36 |
2022-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198799
|
8.6 |
HIGH
Network
|
rockwellautomation
|
armor_compact_guardlogix_5370_firmware compact_guardlogix_5370_firmware compactlogix_5370_l1_firmware compactlogix_5370_l2_firmware compactlogix_5370_l3_firmware controllogix_5570_firm…
|
The connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 versions 33 and prior does not sufficiently manage its control flow during execution, creat…
|
CWE-20
Improper Input Validation
|
CVE-2020-6998
|
2024-11-21 14:36 |
2022-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198800
|
7.8 |
HIGH
Local
|
hp
|
support_assistant
|
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
|
NVD-CWE-noinfo
|
CVE-2020-6922
|
2024-11-21 14:36 |
2022-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|