|
197921
|
5.4 |
MEDIUM
Network
|
ibm
|
api_connect
|
IBM API Connect 5.0.0.0 through 5.0.8.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionalit…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4251
|
2024-11-21 14:32 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197922
|
7.5 |
HIGH
Network
|
scuttlebutt
|
ssb-db
|
SSB-DB version 20.0.0 has an information disclosure vulnerability. The get() method is supposed to only decrypt messages when you explicitly ask it to, but there is a bug where it's decrypting any me…
|
-
|
CVE-2020-4045
|
2024-11-21 14:32 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197923
|
9.8 |
CRITICAL
Network
|
hcltech
|
hcl_digital_experience
|
"HCL Digital Experience is susceptible to Server Side Request Forgery."
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-4101
|
2024-11-21 14:32 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197924
|
5.4 |
MEDIUM
Network
|
ibm
|
workload_scheduler
|
IBM Workload Scheduler 9.3.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potenti…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4380
|
2024-11-21 14:32 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197925
|
9.8 |
CRITICAL
Network
|
phpmussel_project
|
phpmussel
|
phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to an affected version allows arbitrary code execution…
|
-
|
CVE-2020-4043
|
2024-11-21 14:32 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197926
|
7.5 |
HIGH
Network
|
ibm
|
aspera_high-speed_transfer_server_for_cloud_pak_for_integration aspera_shares_on_demand aspera_server_on_demand aspera_faspex_on_demand aspera_application_platform_on_demand aspera_tra…
|
Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code through a s…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-4436
|
2024-11-21 14:32 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197927
|
7.5 |
HIGH
Network
|
ibm
|
aspera_high-speed_transfer_server_for_cloud_pak_for_integration aspera_shares_on_demand aspera_server_on_demand aspera_faspex_on_demand aspera_application_platform_on_demand aspera_tra…
|
Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with intimate knowledge of the system to execute arbitr…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-4435
|
2024-11-21 14:32 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197928
|
7.5 |
HIGH
Network
|
ibm
|
aspera_high-speed_transfer_server_for_cloud_pak_for_integration aspera_shares_on_demand aspera_server_on_demand aspera_faspex_on_demand aspera_application_platform_on_demand aspera_tra…
|
Certain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentication, which could allow an attacker with intimate knowledge of the system to e…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-4434
|
2024-11-21 14:32 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197929
|
7.5 |
HIGH
Network
|
ibm
|
aspera_high-speed_transfer_server_for_cloud_pak_for_integration aspera_shares_on_demand aspera_server_on_demand aspera_faspex_on_demand aspera_application_platform_on_demand aspera_tra…
|
Certain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attacker with intimate knowledge of the server to execut…
|
CWE-20 CWE-787
Improper Input Validation Out-of-bounds Write
|
CVE-2020-4433
|
2024-11-21 14:32 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197930
|
7.5 |
HIGH
Network
|
ibm
|
aspera_high-speed_transfer_server_for_cloud_pak_for_integration aspera_shares_on_demand aspera_server_on_demand aspera_faspex_on_demand aspera_application_platform_on_demand aspera_tra…
|
Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge of the system to execute commands in a SOAP API. …
|
CWE-77
Command Injection
|
CVE-2020-4432
|
2024-11-21 14:32 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|