|
210051
|
7.5 |
HIGH
Network
|
secudos
|
domos
|
conf_datetime in Secudos DOMOS 5.8 allows remote attackers to execute arbitrary commands as root via shell metacharacters in the zone field (obtained from the web interface).
|
CWE-78
OS Command
|
CVE-2020-14293
|
2024-11-21 14:02 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210052
|
6.1 |
MEDIUM
Network
|
hcltech
|
digital_experience
|
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed in a reflected or non-persistent XSS attack.
|
CWE-79
Cross-site Scripting
|
CVE-2020-14223
|
2024-11-21 14:02 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210053
|
5.5 |
MEDIUM
Local
|
apache
|
nifi
|
In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially …
|
CWE-611
XXE
|
CVE-2020-13940
|
2024-11-21 14:02 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210054
|
8.1 |
HIGH
Network
|
apache
|
superset
|
In the course of work on the open source project it was discovered that authenticated users running queries against Hive and Presto database engines could access information via a number of templated…
|
NVD-CWE-noinfo
|
CVE-2020-13952
|
2024-11-21 14:02 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210055
|
7.2 |
HIGH
Network
|
ozeki
|
ozeki_ng_sms_gateway
|
An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. It stores SMS messages in .NET serialized format on the filesystem. By generating (and writing to the disk) malicious .NET serialized f…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-14030
|
2024-11-21 14:02 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210056
|
5.3 |
MEDIUM
Network
|
apache
|
tapestry
|
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2020-13953
|
2024-11-21 14:02 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210057
|
7.5 |
HIGH
Network
|
apache
|
openmeetings
|
Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.
|
NVD-CWE-noinfo
|
CVE-2020-13951
|
2024-11-21 14:02 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210058
|
9.8 |
CRITICAL
Network
|
airforce
|
nitf_extract_utility
|
U.S. Air Force Sensor Data Management System extract75 has a buffer overflow that leads to code execution. An overflow in a global variable (sBuffer) leads to a Write-What-Where outcome. Writing beyo…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13995
|
2024-11-21 14:02 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210059
|
7.5 |
HIGH
Network
|
jerryscript
|
jerryscript
|
vm/opcodes.c in JerryScript 2.2.0 allows attackers to hijack the flow of control by controlling a register.
|
NVD-CWE-noinfo
|
CVE-2020-13991
|
2024-11-21 14:02 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210060
|
7.2 |
HIGH
Network
|
ozeki
|
ozeki_ng_sms_gateway
|
An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The outbox functionality of the TXT File module can be used to delete all/most files in a folder. Because the product usually runs as N…
|
NVD-CWE-noinfo
|
CVE-2020-14031
|
2024-11-21 14:02 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|