|
199541
|
4.3 |
MEDIUM
Network
|
jenkins
|
health_advisor_by_cloudbees
|
A missing permission check in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers with Overall/Read permission to send a fixed email to an attacker-specific recipient.
|
CWE-862
Missing Authorization
|
CVE-2020-2094
|
2024-11-21 14:24 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199542
|
8.8 |
HIGH
Network
|
jenkins
|
health_advisor_by_cloudbees
|
A cross-site request forgery vulnerability in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers to send an email with fixed content to an attacker-specified recipient.
|
CWE-352
Origin Validation Error
|
CVE-2020-2093
|
2024-11-21 14:24 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199543
|
8.8 |
HIGH
Network
|
jenkins
|
robot_framework
|
Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing users with Job/Configure to have Jenkins parse crafted XML do…
|
CWE-611
XXE
|
CVE-2020-2092
|
2024-11-21 14:24 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199544
|
8.1 |
HIGH
Network
|
jenkins
|
amazon_ec2
|
A missing permission check in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL within the AWS region using attacker-spe…
|
CWE-862
Missing Authorization
|
CVE-2020-2091
|
2024-11-21 14:24 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199545
|
8.8 |
HIGH
Network
|
jenkins
|
amazon_ec2
|
A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers to connect to an attacker-specified URL within the AWS region using attacker-specified creden…
|
CWE-352
Origin Validation Error
|
CVE-2020-2090
|
2024-11-21 14:24 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199546
|
9.8 |
CRITICAL
Network
|
leeco
|
letv_x43_firmware
|
An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN02C080080B04121S, allows attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS).
|
NVD-CWE-noinfo
|
CVE-2020-28715
|
2024-11-21 14:23 |
2023-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199547
|
5.4 |
MEDIUM
Network
|
churchcrm
|
churchcrm
|
Cross Site Scripting (XSS) vulnerability in ChurchCRM version 4.2.1, allows remote attckers to execute arbitrary code and gain sensitive information via crafted payload in Add New Deposit field in Vi…
|
CWE-79
Cross-site Scripting
|
CVE-2020-28849
|
2024-11-21 14:23 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199548
|
8.8 |
HIGH
Network
|
churchcrm
|
churchcrm
|
CSV Injection vulnerability in ChurchCRM version 4.2.0, allows remote attackers to execute arbitrary code via crafted CSV file.
|
CWE-74
Injection
|
CVE-2020-28848
|
2024-11-21 14:23 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199549
|
7.8 |
HIGH
Local
|
matthiaswandel
|
jhead
|
Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-28840
|
2024-11-21 14:23 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199550
|
6.1 |
MEDIUM
Network
|
kindsoft
|
kindeditor
|
Cross Site Scripting (XSS) vulnerability in content1 parameter in demo.jsp in kindsoft kindeditor version 4.1.12, allows attackers to execute arbitrary code.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28717
|
2024-11-21 14:23 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|