|
209321
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_mobile
|
An issue was discovered in Mattermost Mobile Apps before 1.30.0. Authorization tokens can sometimes be disclosed to third-party servers, aka MMSA-2020-0018.
|
NVD-CWE-noinfo
|
CVE-2020-14449
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209322
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 5.23.0. Automatic direct message replies allow attackers to cause a denial of service (infinite loop), aka MMSA-2020-0020.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-14448
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209323
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 5.23.0. Large webhook requests allow attackers to cause a denial of service (infinite loop), aka MMSA-2020-0021.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-14447
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209324
|
5.4 |
MEDIUM
Network
|
mitre
|
caldera
|
CALDERA 2.7.0 allows XSS via the Operation Name box.
|
CWE-79
Cross-site Scripting
|
CVE-2020-14462
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209325
|
6.1 |
MEDIUM
Network
|
wso2
|
identity_server_as_key_manager identity_server
|
An issue was discovered in WSO2 Identity Server through 5.10.0 and WSO2 IS as Key Manager through 5.10.0. An open redirect exists.
|
CWE-601
Open Redirect
|
CVE-2020-14446
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209326
|
5.4 |
MEDIUM
Network
|
wso2
|
identity_server identity_server_as_key_manager
|
An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Manag…
|
CWE-79
Cross-site Scripting
|
CVE-2020-14445
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209327
|
5.4 |
MEDIUM
Network
|
wso2
|
identity_server identity_server_as_key_manager
|
An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Manag…
|
CWE-79
Cross-site Scripting
|
CVE-2020-14444
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209328
|
8.8 |
HIGH
Network
|
dolibarr
|
dolibarr
|
A SQL injection vulnerability in accountancy/customer/card.php in Dolibarr 11.0.3 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2020-14443
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209329
|
8.8 |
HIGH
Adjacent
|
netgear
|
rbk752_firmware rbk753_firmware rbk753s_firmware rbr750_firmware rbs750_firmware rbk842_firmware rbr840_firmware rbs840_firmware rbk852_firmware rbk853_firmware rbr850_f…
|
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15…
|
CWE-77
Command Injection
|
CVE-2020-14442
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209330
|
8.8 |
HIGH
Adjacent
|
netgear
|
rbk752_firmware rbk753_firmware rbk753s_firmware rbr750_firmware rbs750_firmware rbk842_firmware rbr840_firmware rbs840_firmware rbk852_firmware rbk853_firmware rbr850_f…
|
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15…
|
CWE-77
Command Injection
|
CVE-2020-14441
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|