|
197031
|
8.8 |
HIGH
Network
|
tibco
|
spotfire_server spotfire_analytics_platform_for_aws
|
The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vulnerability that theoretically allows an attacker …
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-9408
|
2024-11-21 14:40 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197032
|
6.1 |
MEDIUM
Network
|
ckeditor webspellchecker fedoraproject
|
ckeditor webspellchecker fedora
|
A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML el…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9440
|
2024-11-21 14:40 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197033
|
5.4 |
MEDIUM
Network
|
microfocus
|
service_manager
|
There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60. The vulnerability may result in the ability of ma…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-9517
|
2024-11-21 14:40 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197034
|
4.3 |
MEDIUM
Network
|
mahara
|
mahara
|
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access…
|
CWE-200
Information Exposure
|
CVE-2020-9386
|
2024-11-21 14:40 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197035
|
6.5 |
MEDIUM
Network
|
mahara
|
mahara
|
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable inspecting network responses on the 'Edit access' screen when sharing port…
|
CWE-200
Information Exposure
|
CVE-2020-9282
|
2024-11-21 14:40 |
2020-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197036
|
7.8 |
HIGH
Local
|
wftpserver
|
wing_ftp_server
|
An issue was discovered in Wing FTP Server 6.2.5 before February 2020. Due to insecure permissions when handling session cookies, a local user may view the contents of the session and session_admin d…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-9470
|
2024-11-21 14:40 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197037
|
6.1 |
MEDIUM
Network
|
ckeditor fedoraproject drupal oracle
|
ckeditor fedora drupal peoplesoft_enterprise_peopletools webcenter_portal agile_plm application_express jd_edwards_enterpriseone_tools siebel_apps_-_customer_order_management<…
|
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9281
|
2024-11-21 14:40 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197038
|
8.8 |
HIGH
Network
|
metagauss
|
registrationmagic
|
In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the export function allows remote authenticated users (with minimal privileges) to export submitted form data and settings via class_rm_…
|
CWE-862
Missing Authorization
|
CVE-2020-9458
|
2024-11-21 14:40 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197039
|
8.8 |
HIGH
Network
|
metagauss
|
registrationmagic
|
The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable forms and change form settings via class_rm_form_set…
|
CWE-862
Missing Authorization
|
CVE-2020-9457
|
2024-11-21 14:40 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197040
|
8.8 |
HIGH
Network
|
metagauss
|
registrationmagic
|
In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to elevate their privileges to administrator via class_r…
|
CWE-862
Missing Authorization
|
CVE-2020-9456
|
2024-11-21 14:40 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|