|
198801
|
8.8 |
HIGH
Network
|
infolific
|
ultimate_category_excluder
|
The ultimate-category-excluder plugin before 1.2 for WordPress allows ultimate-category-excluder.php CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-35135
|
2024-11-21 14:26 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198802
|
5.4 |
MEDIUM
Network
|
phpldapadmin_project fedoraproject
|
phpldapadmin fedora
|
An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35132
|
2024-11-21 14:26 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198803
|
5.4 |
MEDIUM
Network
|
igniterealtime
|
openfire
|
Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35127
|
2024-11-21 14:26 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198804
|
4.8 |
MEDIUM
Network
|
typesettercms
|
typesetter
|
Typesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI. NOTE: the significance of this report is disputed because "admins are conside…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35126
|
2024-11-21 14:26 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198805
|
7.1 |
HIGH
Network
|
oracle
|
configuration_manager
|
Vulnerability in the Oracle Configuration Manager product of Oracle Enterprise Manager (component: Discovery and collection script). The supported version that is affected is 12.1.2.0.6. Easily explo…
|
NVD-CWE-noinfo
|
CVE-2020-2984
|
2024-11-21 14:26 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198806
|
7.1 |
HIGH
Network
|
oracle
|
data_masking_and_subsetting
|
Vulnerability in the Oracle Data Masking and Subsetting product of Oracle Enterprise Manager (component: Data Masking). Supported versions that are affected are 13.3.0.0 and 13.4.0.0. Easily exploita…
|
NVD-CWE-noinfo
|
CVE-2020-2983
|
2024-11-21 14:26 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198807
|
7.1 |
HIGH
Network
|
oracle
|
enterprise_manager_base_platform
|
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 13.3.0.0 and 13.4.0.0. E…
|
NVD-CWE-noinfo
|
CVE-2020-2982
|
2024-11-21 14:26 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198808
|
7.0 |
HIGH
Local
|
oracle
|
berkeley_db
|
Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version that is affected is Prior to 18.1.40. Difficult to exploit vulnerability allows unauthenticated attacker with lo…
|
NVD-CWE-noinfo
|
CVE-2020-2981
|
2024-11-21 14:26 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198809
|
4.1 |
MEDIUM
Network
|
oracle
|
database
|
Vulnerability in the Oracle Database - Enterprise Edition component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerabili…
|
NVD-CWE-noinfo
|
CVE-2020-2978
|
2024-11-21 14:26 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198810
|
4.6 |
MEDIUM
Network
|
oracle
|
application_express
|
Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker…
|
NVD-CWE-noinfo
|
CVE-2020-2977
|
2024-11-21 14:26 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|