|
197501
|
4.7 |
MEDIUM
Network
|
atlassian
|
confluence confluence_server
|
Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vul…
|
CWE-74
Injection
|
CVE-2020-4027
|
2024-11-21 14:32 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197502
|
4.8 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
The attachment download resource in Atlassian Jira Server and Data Center The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4025
|
2024-11-21 14:32 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197503
|
5.4 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or Ja…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4024
|
2024-11-21 14:32 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197504
|
6.1 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or Ja…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4022
|
2024-11-21 14:32 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197505
|
7.8 |
HIGH
Local
|
neutrinolabs
|
xrdp
|
The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the se…
|
-
|
CVE-2020-4044
|
2024-11-21 14:32 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197506
|
7.5 |
HIGH
Network
|
coturn_project debian fedoraproject canonical opensuse
|
coturn debian_linux fedora ubuntu_linux leap
|
In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an …
|
-
|
CVE-2020-4067
|
2024-11-21 14:32 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197507
|
5.4 |
MEDIUM
Network
|
oauth2_proxy_project
|
oauth2_proxy
|
In OAuth2 Proxy from version 5.1.1 and less than version 6.0.0, users can provide a redirect address for the proxy to send the authenticated user to at the end of the authentication flow. This is exp…
|
-
|
CVE-2020-4037
|
2024-11-21 14:32 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197508
|
5.4 |
MEDIUM
Network
|
ibm
|
business_process_manager business_automation_workflow
|
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4557
|
2024-11-21 14:32 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197509
|
7.5 |
HIGH
Network
|
ibm
|
api_connect
|
IBM API Connect V2018.4.1.0 through 2018.4.1.11 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 181324.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-4452
|
2024-11-21 14:32 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197510
|
6.5 |
MEDIUM
Network
|
hcltech
|
notes
|
HCL Notes is vulnerable to an information leakage vulnerability through its support for the 'mailto' protocol. This vulnerability could result in files from the user's filesystem or connected network…
|
NVD-CWE-noinfo
|
CVE-2020-4089
|
2024-11-21 14:32 |
2020-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|