|
210941
|
8.8 |
HIGH
Network
|
primekey
|
ejbca
|
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. A Cross Site Request Forgery (CSRF) issue has been found in the CA UI.
|
CWE-352
Origin Validation Error
|
CVE-2020-11627
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210942
|
6.1 |
MEDIUM
Network
|
primekey
|
ejbca
|
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. Two Cross Side Scripting (XSS) vulnerabilities have been found in the Public Web and the Certificate/CRL download servlets.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11626
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210943
|
9.8 |
CRITICAL
Network
|
opsramp
|
gateway
|
OpsRamp Gateway before 7.0.0 has a backdoor account vadmin with the password 9vt@f3Vt that allows root SSH access to the server. This issue has been resolved in OpsRamp Gateway firmware version 7.0.0…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-11543
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210944
|
8.1 |
HIGH
Network
|
fasterxml debian netapp oracle
|
jackson-databind debian_linux steelstore_cloud_integrated_storage active_iq_unified_manager retail_xstore_point_of_service primavera_unifier weblogic_server retail_merchandising_…
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-11620
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210945
|
8.1 |
HIGH
Network
|
fasterxml debian netapp oracle
|
jackson-databind debian_linux steelstore_cloud_integrated_storage active_iq_unified_manager retail_xstore_point_of_service primavera_unifier weblogic_server retail_merchandising_…
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-11619
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210946
|
6.1 |
MEDIUM
Network
|
wpleadplus
|
wp_lead_plus_x
|
An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows remote attackers to upload page templates containing arbitrary JavaScript via the c37_wpl_import_template admin-pos…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11509
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210947
|
5.4 |
MEDIUM
Network
|
wpleadplus
|
wp_lead_plus_x
|
An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows logged-in users with minimal permissions to create or replace existing pages with a malicious page containing arbit…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11508
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210948
|
7.5 |
HIGH
Network
|
netty debian fedoraproject netapp oracle
|
netty debian_linux fedora oncommand_workflow_automation oncommand_insight oncommand_api_services webcenter_portal nosql_database communications_messaging_server communicati…
|
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty serve…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-11612
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210949
|
6.1 |
MEDIUM
Network
|
cross_domain_local_storage_project
|
cross_domain_local_storage
|
An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the…
|
CWE-601
Open Redirect
|
CVE-2020-11611
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210950
|
8.8 |
HIGH
Network
|
cross_domain_local_storage_project
|
cross_domain_local_storage
|
An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() funct…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-11610
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|