|
209181
|
5.4 |
MEDIUM
Network
|
bloomreach
|
experience_manager
|
An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows XSS in the login page via the loginmessage parameter, the text editor via the src attribute of HTML ele…
|
CWE-79
Cross-site Scripting
|
CVE-2020-14988
|
2024-11-21 14:04 |
2021-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209182
|
7.2 |
HIGH
Network
|
bloomreach
|
experience_manager
|
An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because there is a mishandling of the capability for adminis…
|
CWE-74 CWE-862
Injection Missing Authorization
|
CVE-2020-14987
|
2024-11-21 14:04 |
2021-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209183
|
9.1 |
CRITICAL
Network
|
loklak_project
|
loklak
|
loklak is an open-source server application which is able to collect messages from various sources, including twitter. The server contains a search index and a peer-to-peer index sharing interface. A…
|
-
|
CVE-2020-15097
|
2024-11-21 14:04 |
2021-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209184
|
9.8 |
CRITICAL
Network
|
oracle
|
utilities_framework coherence
|
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1…
|
NVD-CWE-noinfo
|
CVE-2020-14756
|
2024-11-21 14:04 |
2021-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209185
|
4.7 |
MEDIUM
Network
|
oracle
|
cloud_infrastructure_identity_and_access_management
|
Vulnerability in the Oracle Cloud Infrastructure Identity and Access Management product of Oracle Cloud Services. Easily exploitable vulnerability allows high privileged attacker with network access …
|
NVD-CWE-noinfo
|
CVE-2020-14874
|
2024-11-21 14:04 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209186
|
5.9 |
MEDIUM
Network
|
askey
|
ap5100w_firmware
|
Askey AP5100W devices through AP5100W_Dual_SIG_1.01.097 are affected by WPS PIN offline brute-force cracking. This arises because of issues with the random number selection for the Diffie-Hellman exc…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-15023
|
2024-11-21 14:04 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209187
|
9.8 |
CRITICAL
Network
|
oracle
|
fusion_middleware
|
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.…
|
NVD-CWE-noinfo
|
CVE-2020-14750
|
2024-11-21 14:04 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209188
|
4.8 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.3 allows stats/diagnostic?param= XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15004
|
2024-11-21 14:04 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209189
|
4.3 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string of a different user (via the session API during shared Drive access).
|
NVD-CWE-noinfo
|
CVE-2020-15003
|
2024-11-21 14:04 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209190
|
5.0 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-15002
|
2024-11-21 14:04 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|