|
197561
|
5.4 |
MEDIUM
Network
|
ibm
|
spectrum_protect_client spectrum_protect_for_space_management
|
IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-4406
|
2024-11-21 14:32 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197562
|
3.1 |
LOW
Network
|
wordpress fedoraproject debian
|
wordpress fedora debian_linux
|
In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misus…
|
-
|
CVE-2020-4050
|
2024-11-21 14:32 |
2020-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197563
|
2.4 |
LOW
Network
|
wordpress fedoraproject debian
|
wordpress fedora debian_linux
|
In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does requi…
|
-
|
CVE-2020-4049
|
2024-11-21 14:32 |
2020-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197564
|
5.7 |
MEDIUM
Network
|
wordpress fedoraproject debian
|
wordpress fedora debian_linux
|
In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has…
|
-
|
CVE-2020-4048
|
2024-11-21 14:32 |
2020-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197565
|
6.8 |
MEDIUM
Network
|
wordpress fedoraproject debian
|
wordpress fedora debian_linux
|
In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to sc…
|
-
|
CVE-2020-4047
|
2024-11-21 14:32 |
2020-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197566
|
5.4 |
MEDIUM
Network
|
wordpress debian fedoraproject
|
wordpress debian_linux fedora
|
In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected post…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4046
|
2024-11-21 14:32 |
2020-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197567
|
5.4 |
MEDIUM
Network
|
ibm
|
api_connect
|
IBM API Connect 5.0.0.0 through 5.0.8.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionalit…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4251
|
2024-11-21 14:32 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197568
|
7.5 |
HIGH
Network
|
scuttlebutt
|
ssb-db
|
SSB-DB version 20.0.0 has an information disclosure vulnerability. The get() method is supposed to only decrypt messages when you explicitly ask it to, but there is a bug where it's decrypting any me…
|
-
|
CVE-2020-4045
|
2024-11-21 14:32 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197569
|
9.8 |
CRITICAL
Network
|
hcltech
|
hcl_digital_experience
|
"HCL Digital Experience is susceptible to Server Side Request Forgery."
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-4101
|
2024-11-21 14:32 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197570
|
5.4 |
MEDIUM
Network
|
ibm
|
workload_scheduler
|
IBM Workload Scheduler 9.3.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potenti…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4380
|
2024-11-21 14:32 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|