|
209971
|
9.8 |
CRITICAL
Network
|
soplanning
|
soplanning
|
SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation cod…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-13963
|
2024-11-21 14:02 |
2021-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209972
|
7.5 |
HIGH
Network
|
apache
|
ambari
|
In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files.
|
CWE-22
Path Traversal
|
CVE-2020-13924
|
2024-11-21 14:02 |
2021-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209973
|
6.1 |
MEDIUM
Network
|
apache debian
|
velocity_tools debian_linux
|
The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attacker can set an XSS payload file as this vm file in…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13959
|
2024-11-21 14:02 |
2021-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209974
|
8.8 |
HIGH
Network
|
apache debian oracle
|
velocity_engine wss4j debian_linux retail_order_broker banking_platform communications_network_integrity banking_enterprise_default_management banking_party_management utiliti…
|
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This appl…
|
NVD-CWE-noinfo
|
CVE-2020-13936
|
2024-11-21 14:02 |
2021-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209975
|
7.5 |
HIGH
Network
|
apache oracle
|
thrift hive communications_cloud_native_core_network_slice_selection_function communications_cloud_native_core_policy
|
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-13949
|
2024-11-21 14:02 |
2021-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209976
|
6.1 |
MEDIUM
Network
|
apache oracle
|
activemq communications_session_route_manager communications_session_report_manager
|
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13947
|
2024-11-21 14:02 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209977
|
5.9 |
MEDIUM
Network
|
fedoraproject
|
fedora
|
A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat Enterprise Linux, where it listens on any interface and accepts queri…
|
NVD-CWE-Other
|
CVE-2020-14312
|
2024-11-21 14:02 |
2021-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209978
|
6.5 |
MEDIUM
Network
|
hcltechsw
|
onetest_performance
|
HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid session ID.
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-14247
|
2024-11-21 14:02 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209979
|
7.5 |
HIGH
Network
|
hcltechsw
|
onetest_performance
|
HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak. An attacker could potentially decode the encoded credentials.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-14246
|
2024-11-21 14:02 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209980
|
9.8 |
CRITICAL
Network
|
hcltechsw
|
onetest_performance
|
HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a significant amount of resources.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-14245
|
2024-11-21 14:02 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|