|
209371
|
9.8 |
CRITICAL
Network
|
apache
|
kylin
|
Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; while the reported API misses necessary input validat…
|
CWE-78
OS Command
|
CVE-2020-13925
|
2024-11-21 14:02 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209372
|
8.8 |
HIGH
Local
|
redhat docker
|
enterprise_linux_server docker
|
The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorre…
|
CWE-273
Improper Check for Dropped Privileges
|
CVE-2020-14300
|
2024-11-21 14:02 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209373
|
8.8 |
HIGH
Local
|
redhat docker
|
enterprise_linux_server docker openshift_container_platform
|
The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed…
|
CWE-273
Improper Check for Dropped Privileges
|
CVE-2020-14298
|
2024-11-21 14:02 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209374
|
4.3 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administrati…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-14174
|
2024-11-21 14:02 |
2020-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209375
|
6.5 |
MEDIUM
Network
|
atlassian
|
bitbucket
|
Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a Man-in-the-Middle (MITM) attack.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-14171
|
2024-11-21 14:02 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209376
|
4.3 |
MEDIUM
Network
|
atlassian
|
bitbucket
|
Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vuln…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-14170
|
2024-11-21 14:02 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209377
|
8.8 |
HIGH
Network
|
mods-for-hesk
|
mods_for_hesk
|
An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A privileged user can achieve code execution on the server via a ticket because of improper access control of uploaded resources. This…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-13994
|
2024-11-21 14:02 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209378
|
7.5 |
HIGH
Network
|
mods-for-hesk
|
mods_for_hesk
|
An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A blind time-based SQL injection issue allows remote unauthenticated attackers to retrieve information from the database via a ticket.
|
CWE-89
SQL Injection
|
CVE-2020-13993
|
2024-11-21 14:02 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209379
|
6.1 |
MEDIUM
Network
|
mods-for-hesk
|
mods_for_hesk
|
An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A Stored XSS issue allows remote unauthenticated attackers to abuse a helpdesk user's logged in session. A user with sufficient privil…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13992
|
2024-11-21 14:02 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209380
|
7.5 |
HIGH
Network
|
samba fedoraproject opensuse debian canonical
|
samba fedora leap debian_linux ubuntu_linux
|
A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash.
|
CWE-834
Excessive Iteration
|
CVE-2020-14303
|
2024-11-21 14:02 |
2020-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|