|
210311
|
5.3 |
MEDIUM
Network
|
redhat ibm quarkus oracle
|
hibernate_validator websphere_application_server jboss_enterprise_application_platform satellite_capsule satellite quarkus weblogic_server
|
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attack…
|
-
|
CVE-2020-10693
|
2024-11-21 13:55 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210312
|
9.1 |
CRITICAL
Network
|
sae-it
|
net-line_fw-50_firmware
|
SAE IT-systems FW-50 Remote Telemetry Unit (RTU). A specially crafted request could allow an attacker to view the file structure of the affected device and access files that should be inaccessible.
|
CWE-22
Path Traversal
|
CVE-2020-10634
|
2024-11-21 13:55 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210313
|
6.1 |
MEDIUM
Network
|
sae-it
|
net-line_fw-50_firmware
|
SAE IT-systems FW-50 Remote Telemetry Unit (RTU). The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in the output used as a webpage that is serve…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10630
|
2024-11-21 13:55 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210314
|
6.5 |
MEDIUM
Local
|
qemu
|
qemu
|
A potential DoS flaw was found in the virtio-fs shared file system daemon (virtiofsd) implementation of the QEMU version >= v5.0. Virtio-fs is meant to share a host file system directory with a guest…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-10717
|
2024-11-21 13:55 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210315
|
5.3 |
MEDIUM
Network
|
samba fedoraproject opensuse
|
samba fedora leap
|
A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with the 'ASQ' control. A malicious user in a samba AD could use this flaw to cause de…
|
CWE-416
Use After Free
|
CVE-2020-10700
|
2024-11-21 13:55 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210316
|
4.7 |
MEDIUM
Network
|
redhat
|
keycloak
|
A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post…
|
NVD-CWE-Other
|
CVE-2020-10686
|
2024-11-21 13:55 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210317
|
7.8 |
HIGH
Local
|
lcds
|
laquis_scada
|
LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to arbitrary file creation by unauthorized users
|
NVD-CWE-noinfo
|
CVE-2020-10622
|
2024-11-21 13:55 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210318
|
5.5 |
MEDIUM
Local
|
lcds
|
laquis_scada
|
LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to sensitive information exposure by unauthorized users.
|
CWE-200
Information Exposure
|
CVE-2020-10618
|
2024-11-21 13:55 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210319
|
9.8 |
CRITICAL
Network
|
dom4j_project oracle opensuse netapp canonical
|
dom4j insurance_policy_administration_j2ee insurance_rules_palette retail_integration_bus webcenter_portal utilities_framework flexcube_core_banking business_process_management_s…
|
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing ho…
|
CWE-611
XXE
|
CVE-2020-10683
|
2024-11-21 13:55 |
2020-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210320
|
5.2 |
MEDIUM
Local
|
redhat
|
ansible_engine ansible_tower
|
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is cr…
|
CWE-22
Path Traversal
|
CVE-2020-10691
|
2024-11-21 13:55 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|