|
211051
|
6.5 |
MEDIUM
Network
|
abb generex
|
cs141_firmware
|
UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by manipulating variables that reference files and by do…
|
CWE-22
Path Traversal
|
CVE-2020-11420
|
2024-11-21 13:57 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211052
|
5.4 |
MEDIUM
Network
|
jetbrains
|
space
|
JetBrains Space through 2020-04-22 allows stored XSS in Chats.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11416
|
2024-11-21 13:57 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211053
|
8.8 |
HIGH
Network
|
sonatype
|
nexus
|
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-11444
|
2024-11-21 13:57 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211054
|
5.3 |
MEDIUM
Network
|
microstrategy
|
microstrategy_web
|
Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStrategyWS/. The functionality requires no authentication and,…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-11453
|
2024-11-21 13:57 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211055
|
4.3 |
MEDIUM
Network
|
microstrategy
|
microstrategy_web
|
Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases. By providing an external URL under attacker control, it's possi…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-11452
|
2024-11-21 13:57 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211056
|
5.4 |
MEDIUM
Network
|
microstrategy
|
microstrategy_web
|
Microstrategy Web 10.4 is vulnerable to Stored XSS in the HTML Container and Insert Text features in the window, allowing for the creation of a new dashboard. In order to exploit this vulnerability, …
|
CWE-79
Cross-site Scripting
|
CVE-2020-11454
|
2024-11-21 13:57 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211057
|
7.2 |
HIGH
Network
|
microstrategy
|
microstrategy_web
|
The Upload Visualization plugin in the Microstrategy Web 10.4 admin panel allows an administrator to upload a ZIP archive containing files with arbitrary extensions and data. (This is also exploitabl…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-11451
|
2024-11-21 13:57 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211058
|
7.5 |
HIGH
Network
|
microstrategy
|
microstrategy_web
|
Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information through the URL /MicroStrategyWS/happyaxis.jsp. An attacker could use this vulnerabi…
|
NVD-CWE-noinfo
|
CVE-2020-11450
|
2024-11-21 13:57 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211059
|
4.9 |
MEDIUM
Network
|
misp
|
misp
|
app/Model/feed.php in MISP before 2.4.124 allows administrators to choose arbitrary files that should be ingested by MISP. This does not cause a leak of the full contents of a file, but does cause a …
|
NVD-CWE-noinfo
|
CVE-2020-11458
|
2024-11-21 13:57 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211060
|
3.3 |
LOW
Local
|
zoom
|
meetings
|
Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera ac…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-11470
|
2024-11-21 13:57 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|