|
208961
|
6.1 |
MEDIUM
Network
|
apache
|
airflow
|
The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions prior to 1.10.13. This is same as CVE-2020-13944 but t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-17515
|
2024-11-21 14:08 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208962
|
9.8 |
CRITICAL
Network
|
apache oracle
|
struts business_intelligence communications_policy_management financial_services_data_integration_hub hospitality_opera_5 communications_pricing_design_center mysql_enterprise_monit…
|
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2020-17530
|
2024-11-21 14:08 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208963
|
9.8 |
CRITICAL
Network
|
idreamsoft
|
icms
|
iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php.
|
CWE-78
OS Command
|
CVE-2020-19142
|
2024-11-21 14:08 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208964
|
9.8 |
CRITICAL
Network
|
apache
|
nuttx
|
Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying and invalid fragmentation offs…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-17529
|
2024-11-21 14:08 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208965
|
9.1 |
CRITICAL
Network
|
apache
|
nuttx
|
Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying arbitrary urgent data pointer …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-17528
|
2024-11-21 14:08 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208966
|
9.8 |
CRITICAL
Network
|
apache
|
tapestry
|
A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deseria…
|
-
|
CVE-2020-17531
|
2024-11-21 14:08 |
2020-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208967
|
5.5 |
MEDIUM
Local
|
apache netapp oracle
|
groovy snapcenter primavera_unifier ilearning business_process_management_suite agile_plm retail_bulk_data_integration communications_services_gatekeeper retail_merchandising_…
|
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method c…
|
NVD-CWE-Other
|
CVE-2020-17521
|
2024-11-21 14:08 |
2020-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208968
|
7.5 |
HIGH
Network
|
apache netapp debian oracle
|
tomcat oncommand_system_manager element_plug-in debian_linux instantis_enterprisetrack sd-wan_edge workload_manager mysql_enterprise_monitor communications_cloud_native_core_b…
|
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream re…
|
CWE-200
Information Exposure
|
CVE-2020-17527
|
2024-11-21 14:08 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208969
|
6.5 |
MEDIUM
Network
|
pbootcms
|
pbootcms
|
Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.
|
CWE-352
Origin Validation Error
|
CVE-2020-17901
|
2024-11-21 14:08 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208970
|
5.3 |
MEDIUM
Network
|
untangle
|
untangle_firewall_ng
|
Untangle Firewall NG before 16.0 uses MD5 for passwords.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-17494
|
2024-11-21 14:08 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|