|
199521
|
9.8 |
CRITICAL
Network
|
dell oracle
|
bsafe_crypto-c-micro-edition bsafe_micro-edition-suite http_server security_service database weblogic_server_proxy_plug-in
|
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
|
NVD-CWE-Other
|
CVE-2020-35166
|
2024-11-21 14:26 |
2022-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199522
|
8.1 |
HIGH
Network
|
dell oracle
|
bsafe_crypto-c-micro-edition bsafe_micro-edition-suite http_server security_service database weblogic_server_proxy_plug-in
|
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
|
NVD-CWE-Other
|
CVE-2020-35164
|
2024-11-21 14:26 |
2022-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199523
|
9.8 |
CRITICAL
Network
|
dell oracle
|
bsafe_crypto-c-micro-edition bsafe_micro-edition-suite http_server security_service database weblogic_server_proxy_plug-in
|
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain a Use of Insufficiently Random Values Vulnerability.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-35163
|
2024-11-21 14:26 |
2022-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199524
|
7.5 |
HIGH
Network
|
atomix
|
atomix
|
An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to join a target cluster via providing configuration information.
|
NVD-CWE-noinfo
|
CVE-2020-35209
|
2024-11-21 14:26 |
2021-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199525
|
6.1 |
MEDIUM
Network
|
pixelite
|
events_manager
|
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues
|
-
|
CVE-2020-35037
|
2024-11-21 14:26 |
2021-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199526
|
7.2 |
HIGH
Network
|
pixelite
|
events_manager
|
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection
|
-
|
CVE-2020-35012
|
2024-11-21 14:26 |
2021-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199527
|
9.8 |
CRITICAL
Network
|
windriver oracle
|
vxworks communications_eagle
|
An issue was discovered in Wind River VxWorks 7. The memory allocator has a possible integer overflow in calculating a memory block's size to be allocated by calloc(). As a result, the actual memory …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-35198
|
2024-11-21 14:26 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199528
|
9.8 |
CRITICAL
Network
|
mobileiron
|
mobile\@work
|
The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded encryption key, used to encrypt the submission of username/password details during the authentication process, as demo…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-35138
|
2024-11-21 14:26 |
2021-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199529
|
7.5 |
HIGH
Network
|
mobileiron
|
mobile\@work
|
The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded API key, used to communicate with the MobileIron SaaS discovery API, as demonstrated by Mobile@Work (aka com.mobileiro…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-35137
|
2024-11-21 14:26 |
2021-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199530
|
9.6 |
CRITICAL
Network
|
acquia
|
mautic
|
A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript via mautic[return] (a different attack method than CVE…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35125
|
2024-11-21 14:26 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|