|
211241
|
9.8 |
CRITICAL
Network
|
apache
|
unomi
|
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scri…
|
CWE-74
Injection
|
CVE-2020-13942
|
2024-11-21 14:02 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211242
|
7.5 |
HIGH
Network
|
hcltech
|
notes
|
HCL Notes is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a speciall…
|
CWE-20
Improper Input Validation
|
CVE-2020-14258
|
2024-11-21 14:02 |
2020-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211243
|
7.5 |
HIGH
Network
|
hcltech
|
domino
|
HCL Domino is susceptible to a Denial of Service vulnerability due to improper validation of user-supplied input, potentially giving an attacker the ability to crash the server. Versions previous to …
|
CWE-20
Improper Input Validation
|
CVE-2020-14234
|
2024-11-21 14:02 |
2020-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211244
|
7.5 |
HIGH
Network
|
hcltech
|
domino
|
HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a special…
|
CWE-20
Improper Input Validation
|
CVE-2020-14230
|
2024-11-21 14:02 |
2020-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211245
|
5.4 |
MEDIUM
Network
|
salesagility
|
suitecrm
|
SuiteCRM 7.11.13 is affected by stored Cross-Site Scripting (XSS) in the Documents preview functionality. This vulnerability could allow remote authenticated attackers to inject arbitrary web script …
|
CWE-79
Cross-site Scripting
|
CVE-2020-14208
|
2024-11-21 14:02 |
2020-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211246
|
7.8 |
HIGH
Local
|
apache
|
openoffice
|
A vulnerability in Apache OpenOffice scripting events allows an attacker to construct documents containing hyperlinks pointing to an executable on the target users file system. These hyperlinks can b…
|
NVD-CWE-noinfo
|
CVE-2020-13958
|
2024-11-21 14:02 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211247
|
9.8 |
CRITICAL
Network
|
resourcexpress
|
meeting_monitor
|
SQL Injection issues in various ASPX pages of ResourceXpress Meeting Monitor 4.9 could lead to remote code execution and information disclosure.
|
CWE-89
SQL Injection
|
CVE-2020-13877
|
2024-11-21 14:02 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211248
|
6.1 |
MEDIUM
Network
|
apache netapp oracle
|
cxf snap_creator_framework vasa_provider_for_clustered_data_ontap retail_order_broker_cloud_service business_intelligence communications_messaging_server
|
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13954
|
2024-11-21 14:02 |
2020-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211249
|
9.8 |
CRITICAL
Network
|
atlassian
|
jira_comment
|
The execute function in in the Atlassian gajira-comment GitHub Action before version 2.0.2 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a specially …
|
NVD-CWE-noinfo
|
CVE-2020-14189
|
2024-11-21 14:02 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211250
|
9.8 |
CRITICAL
Network
|
atlassian
|
jira_create
|
The preprocessArgs function in the Atlassian gajira-create GitHub Action before version 2.0.1 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a special…
|
NVD-CWE-noinfo
|
CVE-2020-14188
|
2024-11-21 14:02 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|