|
210131
|
5.3 |
MEDIUM
Network
|
apache
|
ofbiz
|
IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-13923
|
2024-11-21 14:02 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210132
|
7.5 |
HIGH
Network
|
apache debian netapp opensuse canonical mcafee oracle
|
tomcat debian_linux oncommand_system_manager leap ubuntu_linux epolicy_orchestrator managed_file_transfer instantis_enterprisetrack agile_plm workload_manager agile_engi…
|
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could t…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-13935
|
2024-11-21 14:02 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210133
|
7.5 |
HIGH
Network
|
apache debian netapp opensuse canonical oracle
|
tomcat debian_linux oncommand_system_manager leap ubuntu_linux managed_file_transfer instantis_enterprisetrack agile_plm workload_manager agile_engineering_data_management<…
|
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of …
|
CWE-476 CWE-401
NULL Pointer Dereference Missing Release of Memory after Effective Lifetime
|
CVE-2020-13934
|
2024-11-21 14:02 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210134
|
9.8 |
CRITICAL
Network
|
apache
|
kylin
|
Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, while the configuration can be overwritten by certai…
|
CWE-89
SQL Injection
|
CVE-2020-13926
|
2024-11-21 14:02 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210135
|
9.8 |
CRITICAL
Network
|
apache
|
kylin
|
Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; while the reported API misses necessary input validat…
|
CWE-78
OS Command
|
CVE-2020-13925
|
2024-11-21 14:02 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210136
|
8.8 |
HIGH
Local
|
redhat docker
|
enterprise_linux_server docker
|
The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorre…
|
CWE-273
Improper Check for Dropped Privileges
|
CVE-2020-14300
|
2024-11-21 14:02 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210137
|
8.8 |
HIGH
Local
|
redhat docker
|
enterprise_linux_server docker openshift_container_platform
|
The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed…
|
CWE-273
Improper Check for Dropped Privileges
|
CVE-2020-14298
|
2024-11-21 14:02 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210138
|
4.3 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administrati…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-14174
|
2024-11-21 14:02 |
2020-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210139
|
6.5 |
MEDIUM
Network
|
atlassian
|
bitbucket
|
Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a Man-in-the-Middle (MITM) attack.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-14171
|
2024-11-21 14:02 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210140
|
4.3 |
MEDIUM
Network
|
atlassian
|
bitbucket
|
Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vuln…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-14170
|
2024-11-21 14:02 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|