|
210941
|
9.8 |
CRITICAL
Network
|
azkaban_project
|
azkaban
|
Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java.
|
CWE-611
XXE
|
CVE-2020-10992
|
2024-11-21 13:56 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210942
|
9.8 |
CRITICAL
Network
|
mulesoft
|
aplkit
|
Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java
|
CWE-611
XXE
|
CVE-2020-10991
|
2024-11-21 13:56 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210943
|
9.8 |
CRITICAL
Network
|
accenture
|
mercury
|
An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component.
|
CWE-611
XXE
|
CVE-2020-10990
|
2024-11-21 13:56 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210944
|
9.8 |
CRITICAL
Network
|
draytek
|
vigor300b_firmware vigor3900_firmware vigor2960_firmware
|
A stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10828
|
2024-11-21 13:56 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210945
|
9.8 |
CRITICAL
Network
|
draytek
|
vigor300b_firmware vigor3900_firmware vigor2960_firmware
|
A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10827
|
2024-11-21 13:56 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210946
|
9.8 |
CRITICAL
Network
|
draytek
|
vigor300b_firmware vigor3900_firmware vigor2960_firmware
|
/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a remote HTTP request in DEBUG mode.
|
CWE-77
Command Injection
|
CVE-2020-10826
|
2024-11-21 13:56 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210947
|
9.8 |
CRITICAL
Network
|
draytek
|
vigor300b_firmware vigor3900_firmware vigor2960_firmware
|
A stack-based buffer overflow in /cgi-bin/activate.cgi while base64 decoding ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve co…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10825
|
2024-11-21 13:56 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210948
|
9.8 |
CRITICAL
Network
|
draytek
|
vigor300b_firmware vigor3900_firmware vigor2960_firmware
|
A stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution v…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10824
|
2024-11-21 13:56 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210949
|
9.8 |
CRITICAL
Network
|
draytek
|
vigor300b_firmware vigor3900_firmware vigor2960_firmware
|
A stack-based buffer overflow in /cgi-bin/activate.cgi through var parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10823
|
2024-11-21 13:56 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210950
|
8.8 |
HIGH
Network
|
fasterxml debian netapp oracle
|
jackson-databind debian_linux steelstore_cloud_integrated_storage retail_xstore_point_of_service primavera_unifier retail_service_backbone weblogic_server retail_merchandising_sy…
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-10969
|
2024-11-21 13:56 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|