|
199101
|
6.1 |
MEDIUM
Network
|
qnap
|
quts_hero qts
|
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Connection Logs. QANP have already fixed these vulnerabilities in the following v…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2497
|
2024-11-21 14:25 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199102
|
6.1 |
MEDIUM
Network
|
qnap
|
quts_hero qts
|
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2496
|
2024-11-21 14:25 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199103
|
6.1 |
MEDIUM
Network
|
qnap
|
quts_hero qts
|
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2495
|
2024-11-21 14:25 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199104
|
7.5 |
HIGH
Network
|
jenkins
|
cvs
|
Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
CWE-611
XXE
|
CVE-2020-2324
|
2024-11-21 14:25 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199105
|
5.3 |
MEDIUM
Network
|
netflix
|
chaos_monkey
|
Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers with Overall/Read permission to access the Chaos Monkey page and to see the hist…
|
CWE-862
Missing Authorization
|
CVE-2020-2323
|
2024-11-21 14:25 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199106
|
7.5 |
HIGH
Network
|
netflix
|
chaos_monkey
|
Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to generate load and to generate memory leaks.
|
CWE-862
Missing Authorization
|
CVE-2020-2322
|
2024-11-21 14:25 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199107
|
8.1 |
HIGH
Network
|
jenkins
|
shelve_project
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Shelve Project Plugin 3.0 and earlier allows attackers to shelve, unshelve, or delete a project.
|
CWE-352
Origin Validation Error
|
CVE-2020-2321
|
2024-11-21 14:25 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199108
|
9.8 |
CRITICAL
Network
|
jenkins
|
installation_manager_tool
|
Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-2320
|
2024-11-21 14:25 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199109
|
7.2 |
HIGH
Network
|
qnap
|
qts
|
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
|
CWE-77
Command Injection
|
CVE-2020-2492
|
2024-11-21 14:25 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199110
|
7.2 |
HIGH
Network
|
qnap
|
qts
|
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
|
CWE-77
Command Injection
|
CVE-2020-2490
|
2024-11-21 14:25 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|