|
209481
|
5.9 |
MEDIUM
Network
|
apache
|
calcite
|
HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients vulnerable to man-in-the-middle attacks. Calcite uses internally this method to connec…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-13955
|
2024-11-21 14:02 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209482
|
4.3 |
MEDIUM
Network
|
atlassian
|
jira
|
Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vul…
|
CWE-200
Information Exposure
|
CVE-2020-14183
|
2024-11-21 14:02 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209483
|
6.1 |
MEDIUM
Network
|
secudos
|
qiata_fta
|
An issue was discovered in Secudos Qiata FTA 1.70.19. The comment feature allows persistent XSS that is executed when reading transfer comments or the global notice board.
|
CWE-79
Cross-site Scripting
|
CVE-2020-14294
|
2024-11-21 14:02 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209484
|
7.5 |
HIGH
Network
|
secudos
|
domos
|
conf_datetime in Secudos DOMOS 5.8 allows remote attackers to execute arbitrary commands as root via shell metacharacters in the zone field (obtained from the web interface).
|
CWE-78
OS Command
|
CVE-2020-14293
|
2024-11-21 14:02 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209485
|
6.1 |
MEDIUM
Network
|
hcltech
|
digital_experience
|
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed in a reflected or non-persistent XSS attack.
|
CWE-79
Cross-site Scripting
|
CVE-2020-14223
|
2024-11-21 14:02 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209486
|
5.5 |
MEDIUM
Local
|
apache
|
nifi
|
In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially …
|
CWE-611
XXE
|
CVE-2020-13940
|
2024-11-21 14:02 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209487
|
8.1 |
HIGH
Network
|
apache
|
superset
|
In the course of work on the open source project it was discovered that authenticated users running queries against Hive and Presto database engines could access information via a number of templated…
|
NVD-CWE-noinfo
|
CVE-2020-13952
|
2024-11-21 14:02 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209488
|
7.2 |
HIGH
Network
|
ozeki
|
ozeki_ng_sms_gateway
|
An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. It stores SMS messages in .NET serialized format on the filesystem. By generating (and writing to the disk) malicious .NET serialized f…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-14030
|
2024-11-21 14:02 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209489
|
5.3 |
MEDIUM
Network
|
apache
|
tapestry
|
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2020-13953
|
2024-11-21 14:02 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209490
|
7.5 |
HIGH
Network
|
apache
|
openmeetings
|
Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.
|
NVD-CWE-noinfo
|
CVE-2020-13951
|
2024-11-21 14:02 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|