|
196811
|
6.1 |
MEDIUM
Network
|
siemens
|
spectrum_power_5
|
A vulnerability has been identified in Spectrum Power™ 5 (All versions < v5.50 HF02). The web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a …
|
CWE-79
Cross-site Scripting
|
CVE-2020-7579
|
2024-11-21 14:37 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196812
|
7.5 |
HIGH
Network
|
jetbrains
|
scala
|
In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-7907
|
2024-11-21 14:37 |
2020-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196813
|
9.8 |
CRITICAL
Network
|
synacor
|
zimbra_collaboration_suite
|
Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-7796
|
2024-11-21 14:37 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196814
|
9.8 |
CRITICAL
Network
|
freebsd
|
freebsd
|
In FreeBSD 12.1-STABLE before r357213, 12.1-RELEASE before 12.1-RELEASE-p2, 12.0-RELEASE before 12.0-RELEASE-p13, 11.3-STABLE before r357214, and 11.3-RELEASE before 11.3-RELEASE-p6, URL handling in …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7450
|
2024-11-21 14:37 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196815
|
8.8 |
HIGH
Network
|
codecov
|
codecov
|
codecov-node npm module before 3.6.5 allows remote attackers to execute arbitrary commands.The value provided as part of the gcov-root argument is executed by the exec function within lib/codecov.js.…
|
CWE-78
OS Command
|
CVE-2020-7597
|
2024-11-21 14:37 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196816
|
9.8 |
CRITICAL
Network
|
djangoproject
|
django
|
Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data …
|
CWE-89
SQL Injection
|
CVE-2020-7471
|
2024-11-21 14:37 |
2020-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196817
|
6.1 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7913
|
2024-11-21 14:37 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196818
|
5.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-7912
|
2024-11-21 14:37 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196819
|
6.1 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7911
|
2024-11-21 14:37 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196820
|
5.4 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7910
|
2024-11-21 14:37 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|