|
210531
|
8.2 |
HIGH
Network
|
moonlight-stream
|
moonlight
|
In Moonlight iOS/tvOS before 4.0.1, the pairing process is vulnerable to a man-in-the-middle attack. The bug has been fixed in Moonlight v4.0.1 for iOS and tvOS.
|
CWE-200
Information Exposure
|
CVE-2020-11024
|
2024-11-21 13:56 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210532
|
9.8 |
CRITICAL
Network
|
faye_project
|
faye
|
Faye (NPM, RubyGem) versions greater than 0.5.0 and before 1.0.4, 1.1.3 and 1.2.5, has the potential for authentication bypass in the extension system. The vulnerability allows any client to bypass c…
|
CWE-287
Improper Authentication
|
CVE-2020-11020
|
2024-11-21 13:56 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210533
|
6.1 |
MEDIUM
Network
|
jquery debian fedoraproject drupal oracle netapp tenable
|
jquery debian_linux fedora drupal weblogic_server hyperion_financial_reporting webcenter_sites application_testing_suite communications_operations_monitor communications_in…
|
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation m…
|
-
|
CVE-2020-11023
|
2024-11-21 13:56 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210534
|
7.5 |
HIGH
Network
|
http-client_project
|
http-client
|
Actions Http-Client (NPM @actions/http-client) before version 1.0.8 can disclose Authorization headers to incorrect domain in certain redirect scenarios. The conditions in which this happens are if c…
|
NVD-CWE-noinfo
|
CVE-2020-11021
|
2024-11-21 13:56 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210535
|
6.5 |
MEDIUM
Network
|
pagerduty
|
rundeck
|
In Rundeck before version 3.2.6, authenticated users can craft a request that reveals Execution data and logs and Job details that they are not authorized to see. Depending on the configuration and t…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-11009
|
2024-11-21 13:56 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210536
|
6.1 |
MEDIUM
Network
|
netgate
|
pfsense
|
An XSS vulnerability resides in the hostname field of the diag_ping.php page in pfsense before 2.4.5 version. After passing inputs to the command and executing this command, the $result variable is n…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10797
|
2024-11-21 13:56 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210537
|
8.6 |
HIGH
Network
|
simpleledger
|
electron-cash-slp
|
Electron-Cash-SLP before version 3.6.2 has a vulnerability. All token creators that use the "Mint Tool" feature of the Electron Cash SLP Edition are at risk of sending the minting authority baton to …
|
NVD-CWE-noinfo
|
CVE-2020-11014
|
2024-11-21 13:56 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210538
|
5.4 |
MEDIUM
Network
|
hashicorp
|
nomad
|
HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a malicious workload could cause arbitrary JavaScript to execute in the web UI. F…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10944
|
2024-11-21 13:56 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210539
|
6.5 |
MEDIUM
Network
|
percona
|
xtrabackup
|
Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments passed at run time. In addition, when --history is p…
|
CWE-200
Information Exposure
|
CVE-2020-10997
|
2024-11-21 13:56 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210540
|
8.1 |
HIGH
Network
|
percona
|
xtradb_cluster
|
An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.41.2. A bundled script inadvertently sets a static transition_key for SST processes in place of the random key expected.
|
CWE-798 CWE-838
Use of Hard-coded Credentials Inappropriate Encoding for Output Context
|
CVE-2020-10996
|
2024-11-21 13:56 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|