|
198841
|
5.4 |
MEDIUM
Network
|
jenkins
|
matrix_project
|
Jenkins Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes, resulting in a stored cross-site scripting vulnerabi…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2225
|
2024-11-21 14:25 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198842
|
5.4 |
MEDIUM
Network
|
jenkins
|
matrix_project
|
Jenkins Matrix Project Plugin 1.16 and earlier does not escape the node names shown in tooltips on the overview page of builds with a single axis, resulting in a stored cross-site scripting vulnerabi…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2224
|
2024-11-21 14:25 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198843
|
5.4 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of links to downstream jobs displayed in the build console page, resulting in a stored cross-site scr…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2223
|
2024-11-21 14:25 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198844
|
5.4 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored cross-site scripting vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-2222
|
2024-11-21 14:25 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198845
|
6.1 |
MEDIUM
Network
|
oracle
|
primavera_portfolio_management
|
Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Investor Module). Supported versions that are affected are 16.1.0.0-16.1.5.1, 18.0.0.0-1…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2562
|
2024-11-21 14:25 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198846
|
5.4 |
MEDIUM
Network
|
oracle
|
application_express
|
Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2513
|
2024-11-21 14:25 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198847
|
6.5 |
MEDIUM
Network
|
qnap
|
helpdesk
|
This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have rep…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-2500
|
2024-11-21 14:25 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198848
|
7.5 |
HIGH
Local
|
oracle
|
vm_virtualbox
|
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Difficult t…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2020-2575
|
2024-11-21 14:25 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198849
|
6.5 |
MEDIUM
Network
|
oracle
|
primavera_p6_enterprise_project_portfolio_management
|
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Project Manager). Supported versions that are affected are 16.2.0.…
|
NVD-CWE-noinfo
|
CVE-2020-2594
|
2024-11-21 14:25 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198850
|
4.8 |
MEDIUM
Network
|
oracle
|
knowledge
|
Vulnerability in the Oracle Knowledge product of Oracle Knowledge (component: Information Manager Console). Supported versions that are affected are 8.6.0-8.6.3. Difficult to exploit vulnerability al…
|
NVD-CWE-noinfo
|
CVE-2020-2553
|
2024-11-21 14:25 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|