|
196461
|
6.1 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system …
|
In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, an undisclosed TMUI page contains a vulnerability which allows a stored XS…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5915
|
2024-11-21 14:34 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196462
|
7.4 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system …
|
In versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, the BIG-IP Client or Server SSL profile ignores revoked certificates, even when a valid CRL is pre…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-5913
|
2024-11-21 14:34 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196463
|
7.1 |
HIGH
Local
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_advanced_web_application_firewall big-ip_analytics big-ip_application_acceleration_manager big-ip_application_secur…
|
In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the restjavad process's dump command does not follow current best coding p…
|
NVD-CWE-noinfo
|
CVE-2020-5912
|
2024-11-21 14:34 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196464
|
5.4 |
MEDIUM
Network
|
exceedone
|
exment
|
Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary script or HTML via a specially crafted file.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5620
|
2024-11-21 14:34 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196465
|
5.4 |
MEDIUM
Network
|
exceedone
|
exment
|
Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5619
|
2024-11-21 14:34 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196466
|
6.1 |
MEDIUM
Network
|
cybersolutions
|
cybermail
|
Open redirect vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to redirect users to arbitrary sites and conduct phishing attacks via a specially crafted URL.
|
CWE-601
Open Redirect
|
CVE-2020-5541
|
2024-11-21 14:34 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196467
|
6.1 |
MEDIUM
Network
|
cybersolutions
|
cybermail
|
Cross-site scripting vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to inject arbitrary script or HTML via a specially crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5540
|
2024-11-21 14:34 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196468
|
8.8 |
HIGH
Network
|
cloudfoundry
|
cf-deployment capi-release
|
Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also the system domain (which is true in the default CF Deployment manifest), were vu…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-5417
|
2024-11-21 14:34 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196469
|
6.5 |
MEDIUM
Network
|
cloudfoundry
|
cf-deployment routing-release
|
Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in front of the Gorouters, is potentially vulnerable to denial-of-service attacks in …
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2020-5416
|
2024-11-21 14:34 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196470
|
5.8 |
MEDIUM
Network
|
instructure
|
canvas_learning_management_service
|
Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-5775
|
2024-11-21 14:34 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|