|
210931
|
6.1 |
MEDIUM
Network
|
canon
|
oce_colorwave_500_firmware
|
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in the parameter settingId of the settingDialogContent.jsp page. NOTE: this is fixed in the l…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10670
|
2024-11-21 13:55 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210932
|
6.1 |
MEDIUM
Network
|
canon
|
oce_colorwave_500_firmware
|
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in /home.jsp. The vulnerable parameter is openSI. NOTE: this is fixed in the latest version.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10668
|
2024-11-21 13:55 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210933
|
6.1 |
MEDIUM
Network
|
canon
|
oce_colorwave_500_firmware
|
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Stored XSS in /TemplateManager/indexExternalLocation.jsp. The vulnerable parameter is map(template_name). N…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10667
|
2024-11-21 13:55 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210934
|
8.8 |
HIGH
Network
|
octopus
|
octopus_deploy
|
In Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an authenticated user can leverage a bug to escalate privileges.
|
NVD-CWE-noinfo
|
CVE-2020-10678
|
2024-11-21 13:55 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210935
|
7.5 |
HIGH
Network
|
jsonparser_project fedoraproject
|
jsonparser fedora
|
The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via a Delete call.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-10675
|
2024-11-21 13:55 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210936
|
7.8 |
HIGH
Local
|
denx opensuse
|
u-boot leap
|
Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default con…
|
CWE-20
Improper Input Validation
|
CVE-2020-10648
|
2024-11-21 13:55 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210937
|
9.8 |
CRITICAL
Network
|
perlspeak_project
|
perlspeak
|
PerlSpeak through 2.01 allows attackers to execute arbitrary OS commands, as demonstrated by use of system and 2-argument open.
|
CWE-78
OS Command
|
CVE-2020-10674
|
2024-11-21 13:55 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210938
|
6.5 |
MEDIUM
Network
|
logicaldoc
|
logicaldoc
|
LogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the database. This list could be filtered by modifying some of the parameters. Some of t…
|
CWE-89
SQL Injection
|
CVE-2020-10365
|
2024-11-21 13:55 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210939
|
8.8 |
HIGH
Network
|
fasterxml debian netapp oracle
|
jackson-databind debian_linux steelstore_cloud_integrated_storage retail_xstore_point_of_service primavera_unifier retail_service_backbone weblogic_server retail_merchandising_sy…
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
|
NVD-CWE-Other
|
CVE-2020-10673
|
2024-11-21 13:55 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210940
|
8.8 |
HIGH
Network
|
fasterxml debian netapp oracle
|
jackson-databind debian_linux steelstore_cloud_integrated_storage retail_xstore_point_of_service primavera_unifier retail_service_backbone weblogic_server retail_merchandising_sy…
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka…
|
NVD-CWE-Other
|
CVE-2020-10672
|
2024-11-21 13:55 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|