|
198941
|
7.2 |
HIGH
Network
|
qnap
|
qts
|
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
|
CWE-77
Command Injection
|
CVE-2020-2492
|
2024-11-21 14:25 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198942
|
7.2 |
HIGH
Network
|
qnap
|
qts
|
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
|
CWE-77
Command Injection
|
CVE-2020-2490
|
2024-11-21 14:25 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198943
|
6.5 |
MEDIUM
Network
|
jenkins
|
vmware_lab_manager_slaves
|
Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jen…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-2319
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198944
|
6.5 |
MEDIUM
Network
|
jenkins
|
mail_commander
|
Jenkins Mail Commander Plugin for Jenkins-ci Plugin 1.0.0 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Re…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-2318
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198945
|
5.4 |
MEDIUM
Network
|
jenkins
|
findbugs
|
Jenkins FindBugs Plugin 5.0.0 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide r…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2317
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198946
|
5.4 |
MEDIUM
Network
|
jenkins
|
static_analysis_utilities
|
Jenkins Static Analysis Utilities Plugin 1.96 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers w…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2316
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198947
|
6.5 |
MEDIUM
Network
|
jenkins
|
visualworks_store
|
Jenkins Visualworks Store Plugin 1.1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
-
|
CVE-2020-2315
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198948
|
5.5 |
MEDIUM
Local
|
jenkins
|
appspider
|
Jenkins AppSpider Plugin 1.0.12 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins control…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-2314
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198949
|
4.3 |
MEDIUM
Network
|
jenkins
|
azure_key_vault
|
A missing permission check in Jenkins Azure Key Vault Plugin 2.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
|
-
|
CVE-2020-2313
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198950
|
6.5 |
MEDIUM
Network
|
jenkins
|
sqlplus_script_runner
|
Jenkins SQLPlus Script Runner Plugin 2.0.12 and earlier does not mask a password provided as command line argument in build logs.
|
-
|
CVE-2020-2312
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|