|
210551
|
8.8 |
HIGH
Network
|
sonatype
|
nexus_repository_manager_3
|
Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.
|
NVD-CWE-noinfo
|
CVE-2020-15871
|
2024-11-21 14:06 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210552
|
6.1 |
MEDIUM
Network
|
sonatype
|
nexus_repository_manager_3
|
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2).
|
CWE-79
Cross-site Scripting
|
CVE-2020-15870
|
2024-11-21 14:06 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210553
|
5.4 |
MEDIUM
Network
|
sonatype
|
nexus_repository_manager_3
|
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).
|
CWE-79
Cross-site Scripting
|
CVE-2020-15869
|
2024-11-21 14:06 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210554
|
7.7 |
HIGH
Network
|
tgstation13
|
tgstation-server
|
In tgstation-server 4.4.0 and 4.4.1, an authenticated user with permission to download logs can download any file on the server machine (accessible by the owner of the server process) via directory t…
|
CWE-22
Path Traversal
|
CVE-2020-16136
|
2024-11-21 14:06 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210555
|
9.8 |
CRITICAL
Network
|
springblade_project
|
springblade
|
The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.
|
CWE-89
SQL Injection
|
CVE-2020-16165
|
2024-11-21 14:06 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210556
|
7.4 |
HIGH
Network
|
ripe
|
rpki_validator_3
|
An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent rou…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-16164
|
2024-11-21 14:06 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210557
|
9.1 |
CRITICAL
Network
|
ripe
|
rpki_validator_3
|
An issue was discovered in RIPE NCC RPKI Validator 3.x before 3.1-2020.07.06.14.28. RRDP fetches proceed even with a lack of validation of a TLS HTTPS endpoint. This allows remote attackers to bypass…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-16163
|
2024-11-21 14:06 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210558
|
7.5 |
HIGH
Network
|
ripe
|
rpki_validator_3
|
An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. Missing validation checks on CRL presence or CRL staleness in the X509-based RPKI certificate-tree validation proc…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-16162
|
2024-11-21 14:06 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210559
|
5.4 |
MEDIUM
Network
|
nagios
|
log_server
|
A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu.
|
CWE-79
Cross-site Scripting
|
CVE-2020-16157
|
2024-11-21 14:06 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210560
|
3.7 |
LOW
Network
|
linux opensuse fedoraproject debian canonical netapp oracle
|
linux_kernel leap fedora debian_linux ubuntu_linux steelstore_cloud_integrated_storage active_iq_unified_manager solidfire hci_management_node cloud_volumes_ontap_mediator<…
|
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is relat…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-16166
|
2024-11-21 14:06 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|