|
211161
|
6.1 |
MEDIUM
Network
|
apache netapp oracle
|
cxf snap_creator_framework vasa_provider_for_clustered_data_ontap retail_order_broker_cloud_service business_intelligence communications_messaging_server
|
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13954
|
2024-11-21 14:02 |
2020-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211162
|
9.8 |
CRITICAL
Network
|
atlassian
|
jira_comment
|
The execute function in in the Atlassian gajira-comment GitHub Action before version 2.0.2 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a specially …
|
NVD-CWE-noinfo
|
CVE-2020-14189
|
2024-11-21 14:02 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211163
|
9.8 |
CRITICAL
Network
|
atlassian
|
jira_create
|
The preprocessArgs function in the Atlassian gajira-create GitHub Action before version 2.0.1 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a special…
|
NVD-CWE-noinfo
|
CVE-2020-14188
|
2024-11-21 14:02 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211164
|
6.1 |
MEDIUM
Network
|
hcltech
|
notes
|
HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to exec…
|
CWE-79
Cross-site Scripting
|
CVE-2020-14240
|
2024-11-21 14:02 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211165
|
6.1 |
MEDIUM
Network
|
hcltech
|
hcl_digital_experience
|
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a cr…
|
CWE-79
Cross-site Scripting
|
CVE-2020-14222
|
2024-11-21 14:02 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211166
|
5.3 |
MEDIUM
Network
|
apache
|
kylin
|
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, …
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2020-13937
|
2024-11-21 14:02 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211167
|
5.4 |
MEDIUM
Network
|
sage
|
easypay
|
Multiple stored cross-site scripting (XSS) vulnerabilities in Sage EasyPay 10.7.5.10 allow authenticated attackers to inject arbitrary web script or HTML via multiple parameters through Unicode Trans…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13893
|
2024-11-21 14:02 |
2020-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211168
|
6.5 |
MEDIUM
Network
|
redhat
|
single_sign-on openshift_application_runtimes jboss_enterprise_application_platform
|
A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox SecurityDomain, and then reloaded to admin-only mode. T…
|
CWE-287
Improper Authentication
|
CVE-2020-14299
|
2024-11-21 14:02 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211169
|
5.3 |
MEDIUM
Network
|
atlassian
|
jira jira_server
|
Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource. The affected versions are before …
|
CWE-862
Missing Authorization
|
CVE-2020-14185
|
2024-11-21 14:02 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211170
|
7.2 |
HIGH
Network
|
gitea
|
gitea
|
The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the documentation was not understood (e.g., one viewpoint is that…
|
CWE-78
OS Command
|
CVE-2020-14144
|
2024-11-21 14:02 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|