|
208821
|
6.1 |
MEDIUM
Network
|
sap
|
fiori_launchpad_\(news_tile_application\)
|
SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to use SAP Fiori Launchpad News tile Application to send malicious code, to a differen…
|
CWE-79
Cross-site Scripting
|
CVE-2020-26825
|
2024-11-21 14:20 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208822
|
6.1 |
MEDIUM
Network
|
ckeditor oracle
|
ckeditor banking_platform peoplesoft_enterprise_peopletools agile_plm commerce_merchandising jd_edwards_enterpriseone_tools financial_services_analytical_applications_infrastructure…
|
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML co…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27193
|
2024-11-21 14:20 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208823
|
7.2 |
HIGH
Network
|
sapplica
|
sentrifugo
|
In Sentrifugo 3.2, admin can edit employee's informations via this endpoint --> /sentrifugo/index.php/empadditionaldetails/edit/userid/2. In this POST request, "employeeNumId" parameter is affected b…
|
CWE-89
SQL Injection
|
CVE-2020-26805
|
2024-11-21 14:20 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208824
|
8.8 |
HIGH
Network
|
sapplica
|
sentrifugo
|
In Sentrifugo 3.2, users can share an announcement under "Organization -> Announcements" tab. Also, in this page, users can upload attachments with the shared announcements. This "Upload Attachment" …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-26804
|
2024-11-21 14:20 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208825
|
8.8 |
HIGH
Network
|
sapplica
|
sentrifugo
|
In Sentrifugo 3.2, users can upload an image under "Assets -> Add" tab. This "Upload Images" functionality is suffered from "Unrestricted File Upload" vulnerability so attacker can upload malicious f…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-26803
|
2024-11-21 14:20 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208826
|
10.0 |
CRITICAL
Network
|
sap
|
solution_manager
|
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Legacy Ports Service, this has an…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-26824
|
2024-11-21 14:20 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208827
|
8.8 |
HIGH
Network
|
tibco
|
iprocess_workspace_browser
|
The Core component of TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser) contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a Cross Si…
|
CWE-352
Origin Validation Error
|
CVE-2020-27146
|
2024-11-21 14:20 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208828
|
10.0 |
CRITICAL
Network
|
sap
|
solution_manager
|
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Diagnostics Agent Connection Serv…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-26823
|
2024-11-21 14:20 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208829
|
10.0 |
CRITICAL
Network
|
sap
|
solution_manager
|
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Outside Discovery Configuration Service, …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-26822
|
2024-11-21 14:20 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208830
|
10.0 |
CRITICAL
Network
|
sap
|
solution_manager
|
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the SVG Converter Service, this has an impact…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-26821
|
2024-11-21 14:20 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|