|
200321
|
3.0 |
LOW
Network
|
paloaltonetworks
|
pan-os
|
When SSL/TLS Forward Proxy Decryption mode has been configured to decrypt the web transactions, the PAN-OS URL filtering feature inspects the HTTP Host and URL path headers for policy enforcement on …
|
NVD-CWE-noinfo
|
CVE-2020-2035
|
2024-11-21 14:24 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200322
|
6.5 |
MEDIUM
Network
|
sick
|
package_analytics
|
Passwords are stored in plain text within the configuration of SICK Package Analytics software up to and including V04.1.1. An authorized attacker could access these stored plaintext credentials and …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-2078
|
2024-11-21 14:24 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200323
|
7.5 |
HIGH
Network
|
sick
|
package_analytics
|
SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized attacker could read sensitive data from the system by…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-2077
|
2024-11-21 14:24 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200324
|
9.8 |
CRITICAL
Network
|
sick
|
package_analytics
|
SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with the REST API. An attacker can send unauthorized requests, b…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-2076
|
2024-11-21 14:24 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200325
|
5.4 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-2221
|
2024-11-21 14:24 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200326
|
5.4 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-2220
|
2024-11-21 14:24 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200327
|
8.1 |
HIGH
Network
|
paloaltonetworks
|
pan-os
|
An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacker to execute arbitrary OS commands with root privileges. An attacker requires s…
|
CWE-78
OS Command
|
CVE-2020-2034
|
2024-11-21 14:24 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200328
|
4.9 |
MEDIUM
Network
|
paloaltonetworks
|
pan-os
|
An integer underflow vulnerability in the dnsproxyd component of the PAN-OS management interface allows authenticated administrators to issue a command from the command line interface that causes the…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2020-2031
|
2024-11-21 14:24 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200329
|
7.2 |
HIGH
Network
|
paloaltonetworks
|
pan-os
|
An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts PAN-OS 8.1 …
|
CWE-78
OS Command
|
CVE-2020-2030
|
2024-11-21 14:24 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200330
|
5.4 |
MEDIUM
Network
|
jenkins
|
link_column
|
Jenkins Link Column Plugin 1.0 and earlier does not filter URLs of links created by users with View/Configure permission, resulting in a stored cross-site scripting vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-2219
|
2024-11-21 14:24 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|