|
209581
|
5.3 |
MEDIUM
Network
|
powerdns
|
recursor
|
In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enforced.
|
CWE-863
Incorrect Authorization
|
CVE-2020-14196
|
2024-11-21 14:02 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209582
|
9.8 |
CRITICAL
Network
|
monstaftp
|
monsta_ftp
|
Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code exec…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2020-14057
|
2024-11-21 14:02 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209583
|
9.8 |
CRITICAL
Network
|
monstaftp
|
monsta_ftp
|
Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arbitrary local files …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-14056
|
2024-11-21 14:02 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209584
|
6.1 |
MEDIUM
Network
|
monstaftp
|
monsta_ftp
|
Monsta FTP 2.10.1 or below is prone to a stored cross-site scripting vulnerability in the language setting due to insufficient output encoding.
|
CWE-79
Cross-site Scripting
|
CVE-2020-14055
|
2024-11-21 14:02 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209585
|
6.1 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center
|
The quick search component in Atlassian Jira Server and Data Center before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability
|
CWE-79
Cross-site Scripting
|
CVE-2020-14169
|
2024-11-21 14:02 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209586
|
5.9 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
The email client in Jira Server and Data Center before version 7.13.16, from 8.5.0 before 8.5.7, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to access outgoing emails…
|
NVD-CWE-noinfo
|
CVE-2020-14168
|
2024-11-21 14:02 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209587
|
7.5 |
HIGH
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 before 8.5.5, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to impac…
|
NVD-CWE-noinfo
|
CVE-2020-14167
|
2024-11-21 14:02 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209588
|
4.8 |
MEDIUM
Network
|
atlassian
|
jira_service_desk
|
The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remote attackers with project administrator privileges to inject arbitrary HTML or …
|
CWE-79
Cross-site Scripting
|
CVE-2020-14166
|
2024-11-21 14:02 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209589
|
5.3 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center
|
The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote attackers to obtain information about custom project avatars names via an Improper au…
|
NVD-CWE-noinfo
|
CVE-2020-14165
|
2024-11-21 14:02 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209590
|
6.1 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center
|
The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by…
|
CWE-79
Cross-site Scripting
|
CVE-2020-14164
|
2024-11-21 14:02 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|