|
210041
|
5.4 |
MEDIUM
Network
|
sage
|
easypay
|
Multiple stored cross-site scripting (XSS) vulnerabilities in Sage EasyPay 10.7.5.10 allow authenticated attackers to inject arbitrary web script or HTML via multiple parameters through Unicode Trans…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13893
|
2024-11-21 14:02 |
2020-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210042
|
6.5 |
MEDIUM
Network
|
redhat
|
single_sign-on openshift_application_runtimes jboss_enterprise_application_platform
|
A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox SecurityDomain, and then reloaded to admin-only mode. T…
|
CWE-287
Improper Authentication
|
CVE-2020-14299
|
2024-11-21 14:02 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210043
|
5.3 |
MEDIUM
Network
|
atlassian
|
jira jira_server
|
Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource. The affected versions are before …
|
CWE-862
Missing Authorization
|
CVE-2020-14185
|
2024-11-21 14:02 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210044
|
7.2 |
HIGH
Network
|
gitea
|
gitea
|
The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the documentation was not understood (e.g., one viewpoint is that…
|
CWE-78
OS Command
|
CVE-2020-14144
|
2024-11-21 14:02 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210045
|
9.8 |
CRITICAL
Network
|
apache
|
solr
|
Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that…
|
CWE-863
Incorrect Authorization
|
CVE-2020-13957
|
2024-11-21 14:02 |
2020-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210046
|
4.3 |
MEDIUM
Network
|
apache debian oracle
|
tomcat debian_linux instantis_enterprisetrack sd-wan_edge
|
If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation o…
|
NVD-CWE-noinfo
|
CVE-2020-13943
|
2024-11-21 14:02 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210047
|
5.4 |
MEDIUM
Network
|
atlassian
|
jira jira_server
|
Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in Jira issue filter export files. The affected…
|
CWE-79
Cross-site Scripting
|
CVE-2020-14184
|
2024-11-21 14:02 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210048
|
5.9 |
MEDIUM
Network
|
apache
|
calcite
|
HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients vulnerable to man-in-the-middle attacks. Calcite uses internally this method to connec…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-13955
|
2024-11-21 14:02 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210049
|
4.3 |
MEDIUM
Network
|
atlassian
|
jira
|
Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vul…
|
CWE-200
Information Exposure
|
CVE-2020-14183
|
2024-11-21 14:02 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210050
|
6.1 |
MEDIUM
Network
|
secudos
|
qiata_fta
|
An issue was discovered in Secudos Qiata FTA 1.70.19. The comment feature allows persistent XSS that is executed when reading transfer comments or the global notice board.
|
CWE-79
Cross-site Scripting
|
CVE-2020-14294
|
2024-11-21 14:02 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|