|
209991
|
7.5 |
HIGH
Network
|
apache
|
jackrabbit_oak
|
The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitive information disclosure vulnerability. The code mandates…
|
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2020-1940
|
2024-11-21 14:11 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209992
|
6.1 |
MEDIUM
Network
|
apache
|
nifi
|
A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in othe…
|
CWE-79
Cross-site Scripting
|
CVE-2020-1933
|
2024-11-21 14:11 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209993
|
6.5 |
MEDIUM
Network
|
apache
|
superset
|
An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed pa…
|
NVD-CWE-noinfo
|
CVE-2020-1932
|
2024-11-21 14:11 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209994
|
5.3 |
MEDIUM
Network
|
apache
|
nifi
|
An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a s…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-1928
|
2024-11-21 14:11 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209995
|
5.5 |
MEDIUM
Local
|
huawei
|
honor_v30_firmware
|
Honor V30 smartphones with versions earlier than 10.0.1.135(C00E130R4P1) have an improper authentication vulnerability. Certain applications do not properly validate the identity of another applicati…
|
CWE-287
Improper Authentication
|
CVE-2020-1788
|
2024-11-21 14:11 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209996
|
6.0 |
MEDIUM
Local
|
huawei
|
mate_20_firmware
|
HUAWEI Mate 20 smart phones with versions earlier than 10.0.0.175(C00E70R3P8) have an insufficient authentication vulnerability. A local attacker with high privilege can execute a specific command to…
|
CWE-287
Improper Authentication
|
CVE-2020-1840
|
2024-11-21 14:11 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209997
|
7.5 |
HIGH
Network
|
apache
|
beam
|
The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to disable SSL trust verification. However this configuration is not respected and the certificate verification disables t…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-1929
|
2024-11-21 14:11 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209998
|
4.3 |
MEDIUM
Network
|
otrs debian
|
otrs debian_linux
|
Agent A is able to save a draft (i.e. for customer reply). Then Agent B can open the draft, change the text completely and send it in the name of Agent A. For the customer it will not be visible that…
|
NVD-CWE-Other
|
CVE-2020-1767
|
2024-11-21 14:11 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209999
|
6.1 |
MEDIUM
Network
|
otrs debian
|
otrs debian_linux
|
Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious javascript from a special crafted SVG file rendered as…
|
CWE-79
Cross-site Scripting
|
CVE-2020-1766
|
2024-11-21 14:11 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210000
|
5.3 |
MEDIUM
Network
|
otrs debian opensuse
|
otrs debian_linux leap backports_sle
|
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue a…
|
NVD-CWE-Other
|
CVE-2020-1765
|
2024-11-21 14:11 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|