|
210401
|
4.8 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.3 allows stats/diagnostic?param= XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15004
|
2024-11-21 14:04 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210402
|
4.3 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string of a different user (via the session API during shared Drive access).
|
NVD-CWE-noinfo
|
CVE-2020-15003
|
2024-11-21 14:04 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210403
|
5.0 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-15002
|
2024-11-21 14:04 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210404
|
4.9 |
MEDIUM
Network
|
oracle
|
database
|
Vulnerability in the RDBMS Security component of Oracle Database Server. The supported version that is affected is 19c. Easily exploitable vulnerability allows high privileged attacker having Analyze…
|
NVD-CWE-noinfo
|
CVE-2020-14901
|
2024-11-21 14:04 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210405
|
5.4 |
MEDIUM
Network
|
oracle
|
application_express
|
Vulnerability in the Oracle Application Express Group Calendar component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows lo…
|
NVD-CWE-noinfo
|
CVE-2020-14900
|
2024-11-21 14:04 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210406
|
5.4 |
MEDIUM
Network
|
oracle
|
application_express
|
Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low…
|
NVD-CWE-noinfo
|
CVE-2020-14899
|
2024-11-21 14:04 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210407
|
5.4 |
MEDIUM
Network
|
oracle
|
application_express
|
Vulnerability in the Oracle Application Express Packaged Apps component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low…
|
NVD-CWE-noinfo
|
CVE-2020-14898
|
2024-11-21 14:04 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210408
|
6.5 |
MEDIUM
Network
|
oracle
|
flexcube_direct_banking
|
Vulnerability in the Oracle FLEXCUBE Direct Banking product of Oracle Financial Services Applications (component: Pre Login). Supported versions that are affected are 12.0.1, 12.0.2 and 12.0.3. Easil…
|
NVD-CWE-noinfo
|
CVE-2020-14897
|
2024-11-21 14:04 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210409
|
6.5 |
MEDIUM
Network
|
oracle
|
banking_payments
|
Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core). Supported versions that are affected are 14.1.0-14.4.0. Easily exploitable vulnerabil…
|
NVD-CWE-noinfo
|
CVE-2020-14896
|
2024-11-21 14:04 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210410
|
5.4 |
MEDIUM
Network
|
oracle
|
utilities_framework
|
Vulnerability in the Oracle Utilities Framework product of Oracle Utilities Applications (component: System Wide). Supported versions that are affected are 2.2.0.0.0, 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0 …
|
NVD-CWE-noinfo
|
CVE-2020-14895
|
2024-11-21 14:04 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|