|
209551
|
7.5 |
HIGH
Network
|
ruckuswireless
|
unleashed_firmware
|
webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to cause a denial of service (Segmentation fault) to the webserver via an unauthenticated crafted HTTP request. This…
|
NVD-CWE-noinfo
|
CVE-2020-13914
|
2024-11-21 14:02 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209552
|
6.1 |
MEDIUM
Network
|
ruckuswireless
|
unleashed_firmware
|
An XSS issue in emfd in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute JavaScript code via an unauthenticated crafted HTTP request. This affects C110, E510, H32…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13913
|
2024-11-21 14:02 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209553
|
6.5 |
MEDIUM
Network
|
redhat
|
jboss_fuse single_sign-on openshift_application_runtimes jboss_enterprise_application_platform_continuous_delivery amq
|
A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a …
|
-
|
CVE-2020-14307
|
2024-11-21 14:02 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209554
|
6.5 |
MEDIUM
Network
|
redhat
|
jboss_fuse single_sign-on openshift_application_runtimes jboss_enterprise_application_platform_continuous_delivery amq jboss-ejb-client
|
A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down an…
|
-
|
CVE-2020-14297
|
2024-11-21 14:02 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209555
|
5.4 |
MEDIUM
Network
|
atlassian
|
confluence_server confluence_data_center
|
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters.…
|
CWE-79
Cross-site Scripting
|
CVE-2020-14175
|
2024-11-21 14:02 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209556
|
6.1 |
MEDIUM
Network
|
tc_custom_javascript_project
|
tc_custom_javascript
|
A stored Cross-Site Scripting (XSS) vulnerability in the TC Custom JavaScript plugin before 1.2.2 for WordPress allows unauthenticated remote attackers to inject arbitrary JavaScript via the tccj-con…
|
CWE-79
Cross-site Scripting
|
CVE-2020-14063
|
2024-11-21 14:02 |
2020-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209557
|
6.1 |
MEDIUM
Network
|
apache
|
activemq_artemis
|
In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into …
|
CWE-79
Cross-site Scripting
|
CVE-2020-13932
|
2024-11-21 14:02 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209558
|
5.3 |
MEDIUM
Network
|
golang opensuse
|
go leap
|
In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Window…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-14039
|
2024-11-21 14:02 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209559
|
9.8 |
CRITICAL
Network
|
kramdown_project debian fedoraproject canonical
|
kramdown debian_linux fedora ubuntu_linux
|
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded …
|
CWE-862
Missing Authorization
|
CVE-2020-14001
|
2024-11-21 14:02 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209560
|
9.8 |
CRITICAL
Network
|
mit
|
scratch-vm
|
MIT Lifelong Kindergarten Scratch scratch-vm before 0.2.0-prerelease.20200714185213 loads extension URLs from untrusted project.json files with certain _ characters, resulting in remote code executio…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-14000
|
2024-11-21 14:02 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|