|
197441
|
7.5 |
HIGH
Network
|
cncf redhat debian
|
envoy openshift_service_mesh debian_linux
|
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-8659
|
2024-11-21 14:39 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197442
|
9.8 |
CRITICAL
Network
|
zyxel
|
nas326_firmware nas520_firmware nas540_firmware nas542_firmware atp100_firmware atp200_firmware atp500_firmware atp800_firmware usg20-vpn_firmware usg20w-vpn_firmware us…
|
Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to…
|
CWE-78
OS Command
|
CVE-2020-9054
|
2024-11-21 14:39 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197443
|
5.4 |
MEDIUM
Network
|
alfresco
|
alfresco
|
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write access to a project.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8778
|
2024-11-21 14:39 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197444
|
5.4 |
MEDIUM
Network
|
alfresco
|
alfresco
|
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT element in an SVG document.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8777
|
2024-11-21 14:39 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197445
|
5.4 |
MEDIUM
Network
|
alfresco
|
alfresco
|
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a file.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8776
|
2024-11-21 14:39 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197446
|
6.1 |
MEDIUM
Network
|
fiserv
|
accurate_reconciliation
|
Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the logout.jsp timeOut parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8952
|
2024-11-21 14:39 |
2020-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197447
|
5.4 |
MEDIUM
Network
|
fiserv
|
accurate_reconciliation
|
Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the Source or Destination field of the Configuration Manager (Configuration Parameter Translation) page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8951
|
2024-11-21 14:39 |
2020-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197448
|
8.1 |
HIGH
Network
|
gurux
|
device_language_message_specification_director
|
An issue was discovered in Gurux GXDLMS Director through 8.5.1905.1301. When downloading OBIS codes, it does not verify that the downloaded files are actual OBIS codes and doesn't check for path trav…
|
CWE-22
Path Traversal
|
CVE-2020-8810
|
2024-11-21 14:39 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197449
|
8.1 |
HIGH
Network
|
gurux
|
device_language_message_specification_director
|
Gurux GXDLMS Director prior to 8.5.1905.1301 downloads updates to add-ins and OBIS code over an unencrypted HTTP connection. A man-in-the-middle attacker can prompt the user to download updates by mo…
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-8809
|
2024-11-21 14:39 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197450
|
6.1 |
MEDIUM
Network
|
wpjobboard
|
wpjobboard
|
The WPJobBoard plugin 5.5.3 for WordPress allows Persistent XSS via the Add Job form, as demonstrated by title and Description.
|
CWE-79
Cross-site Scripting
|
CVE-2020-9019
|
2024-11-21 14:39 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|