|
196821
|
6.1 |
MEDIUM
Network
|
cybersolutions
|
cybermail
|
Cross-site scripting vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to inject arbitrary script or HTML via a specially crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5540
|
2024-11-21 14:34 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196822
|
8.8 |
HIGH
Network
|
cloudfoundry
|
cf-deployment capi-release
|
Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also the system domain (which is true in the default CF Deployment manifest), were vu…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-5417
|
2024-11-21 14:34 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196823
|
6.5 |
MEDIUM
Network
|
cloudfoundry
|
cf-deployment routing-release
|
Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in front of the Gorouters, is potentially vulnerable to denial-of-service attacks in …
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2020-5416
|
2024-11-21 14:34 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196824
|
5.8 |
MEDIUM
Network
|
instructure
|
canvas_learning_management_service
|
Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-5775
|
2024-11-21 14:34 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196825
|
7.1 |
HIGH
Local
|
tenable
|
nessus
|
Nessus versions 8.11.0 and earlier were found to maintain sessions longer than the permitted period in certain scenarios. The lack of proper session expiration could allow attackers with local access…
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-5774
|
2024-11-21 14:34 |
2020-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196826
|
7.8 |
HIGH
Local
|
dell
|
endpoint_security_suite_enterprise encryption
|
Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escalation vulnerability because of an incomplete fix for CVE-2020-5358. A local mali…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-5385
|
2024-11-21 14:34 |
2020-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196827
|
10.0 |
CRITICAL
Network
|
pivotal_software
|
concourse
|
Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with the same full name a…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2020-5415
|
2024-11-21 14:34 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196828
|
6.5 |
MEDIUM
Network
|
vmware
|
spring_cloud_netflix
|
Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make reques…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2020-5412
|
2024-11-21 14:34 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196829
|
9.8 |
CRITICAL
Network
|
yokogawa
|
centum_cs_3000_firmware centum_vp_firmware b\/m9000cs_firmware b\/m9000vp_firmware
|
Directory traversal vulnerability in CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.0…
|
CWE-22
Path Traversal
|
CVE-2020-5609
|
2024-11-21 14:34 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196830
|
9.8 |
CRITICAL
Network
|
yokogawa
|
centum_cs_3000_firmware centum_vp_firmware b\/m9000cs_firmware b\/m9000vp_firmware
|
CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, and B/M9000 VP R6.0…
|
CWE-287
Improper Authentication
|
CVE-2020-5608
|
2024-11-21 14:34 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|