|
209061
|
6.5 |
MEDIUM
Network
|
redhat
|
single_sign-on keycloak
|
A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be …
|
-
|
CVE-2020-27838
|
2024-11-21 14:21 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209062
|
5.4 |
MEDIUM
Network
|
maxum
|
rumpus
|
Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site scripting (XSS). Users are able to create folders in the web application. The folder name is insufficiently validated resulting in a stored cr…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27576
|
2024-11-21 14:21 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209063
|
8.8 |
HIGH
Network
|
maxum
|
rumpus
|
Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability. The web administration contains functionality in which administrators are able to manage users. The edit users form co…
|
CWE-78
OS Command
|
CVE-2020-27575
|
2024-11-21 14:21 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209064
|
8.8 |
HIGH
Network
|
maxum
|
rumpus
|
Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site request forgery (CSRF). If an authenticated user visits a malicious page, unintended actions could be performed in the web application as the …
|
CWE-352
Origin Validation Error
|
CVE-2020-27574
|
2024-11-21 14:21 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209065
|
7.5 |
HIGH
Local
|
gnu redhat fedoraproject netapp
|
grub2 enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux enterprise_linux_server_tus enterprise_linux_server_eus fedora ontap_select_deploy_administration_…
|
A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity…
|
NVD-CWE-Other
|
CVE-2020-27779
|
2024-11-21 14:21 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209066
|
6.7 |
MEDIUM
Local
|
gnu redhat fedoraproject netapp
|
grub2 enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux enterprise_linux_server_tus enterprise_linux_server_eus fedora ontap_select_deploy_administration_…
|
A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line into their corresponding variable contents, using a 1kB stack buffer for temporar…
|
-
|
CVE-2020-27749
|
2024-11-21 14:21 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209067
|
5.5 |
MEDIUM
Local
|
gnu netapp oracle debian
|
glibc ontap_select_deploy_administration_utility a250_firmware 500f_firmware h410c_firmware h300s_firmware h500s_firmware h700s_firmware h300e_firmware h500e_firmware h7…
|
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails t…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-27618
|
2024-11-21 14:21 |
2021-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209068
|
7.5 |
HIGH
Network
|
restify-paginate_project
|
restify-paginate
|
The restify-paginate package 0.0.5 for Node.js allows remote attackers to cause a Denial-of-Service by omitting the HTTP Host header. A Restify-based web service would crash with an uncaught exceptio…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-27543
|
2024-11-21 14:21 |
2021-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209069
|
7.5 |
HIGH
Network
|
redhat
|
jboss_fuse openshift_application_runtimes undertow
|
A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a …
|
-
|
CVE-2020-27782
|
2024-11-21 14:21 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209070
|
5.5 |
MEDIUM
Local
|
libxls_project
|
libxls
|
An issue was discovered in libxls before and including 1.6.1 when reading Microsoft Excel files. A NULL pointer dereference vulnerability exists when parsing XLS cells in libxls/xls2csv.c:199. It cou…
|
-
|
CVE-2020-27819
|
2024-11-21 14:21 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|