|
199711
|
8.8 |
HIGH
Network
|
jenkins
|
robot_framework
|
Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing users with Job/Configure to have Jenkins parse crafted XML do…
|
CWE-611
XXE
|
CVE-2020-2092
|
2024-11-21 14:24 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199712
|
8.1 |
HIGH
Network
|
jenkins
|
amazon_ec2
|
A missing permission check in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL within the AWS region using attacker-spe…
|
CWE-862
Missing Authorization
|
CVE-2020-2091
|
2024-11-21 14:24 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199713
|
8.8 |
HIGH
Network
|
jenkins
|
amazon_ec2
|
A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers to connect to an attacker-specified URL within the AWS region using attacker-specified creden…
|
CWE-352
Origin Validation Error
|
CVE-2020-2090
|
2024-11-21 14:24 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199714
|
9.8 |
CRITICAL
Network
|
leeco
|
letv_x43_firmware
|
An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN02C080080B04121S, allows attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS).
|
NVD-CWE-noinfo
|
CVE-2020-28715
|
2024-11-21 14:23 |
2023-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199715
|
5.4 |
MEDIUM
Network
|
churchcrm
|
churchcrm
|
Cross Site Scripting (XSS) vulnerability in ChurchCRM version 4.2.1, allows remote attckers to execute arbitrary code and gain sensitive information via crafted payload in Add New Deposit field in Vi…
|
CWE-79
Cross-site Scripting
|
CVE-2020-28849
|
2024-11-21 14:23 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199716
|
8.8 |
HIGH
Network
|
churchcrm
|
churchcrm
|
CSV Injection vulnerability in ChurchCRM version 4.2.0, allows remote attackers to execute arbitrary code via crafted CSV file.
|
CWE-74
Injection
|
CVE-2020-28848
|
2024-11-21 14:23 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199717
|
7.8 |
HIGH
Local
|
matthiaswandel
|
jhead
|
Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-28840
|
2024-11-21 14:23 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199718
|
6.1 |
MEDIUM
Network
|
kindsoft
|
kindeditor
|
Cross Site Scripting (XSS) vulnerability in content1 parameter in demo.jsp in kindsoft kindeditor version 4.1.12, allows attackers to execute arbitrary code.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28717
|
2024-11-21 14:23 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199719
|
9.8 |
CRITICAL
Network
|
mediawiki
|
score
|
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit artic…
|
CWE-94
Code Injection
|
CVE-2020-29007
|
2024-11-21 14:23 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199720
|
9.8 |
CRITICAL
Network
|
zend
|
zend_framework
|
An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and inc…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-29312
|
2024-11-21 14:23 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|