Latest CVE Feed
-
6.1
MEDIUMCVE-2020-9485
An issue was found in Apache Airflow versions 1.10.10 and below. A stored XSS vulnerability was discovered in the Chart pages of the the "classic" UI.... Read more
Affected Products : airflow- Published: Jul. 17, 2020
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2020-9484
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceMa... Read more
Affected Products : ubuntu_linux fedora debian_linux leap agile_engineering_data_management database siebel_ui_framework mysql_enterprise_monitor tomcat hospitality_guest_access +16 more products- Published: May. 20, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9483
**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is a SQL injection vulnerability, which allows to access unpexcted data. Apache SkyWalking 6.0.0 to 6.6.0, 7.0.0 H2/MySQL/TiDB storage imp... Read more
Affected Products : skywalking- Published: Jun. 30, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2020-9482
If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Registry invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to b... Read more
Affected Products : nifi_registry- Published: Apr. 28, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9481
Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.... Read more
- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-9480
In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an applica... Read more
- Published: Jun. 23, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-9479
When loading a UDF, a specially crafted zip file could allow files to be placed outside of the UDF deployment directory. This issue affected Apache AsterixDB unreleased builds between commits 580b81aa5e8888b8e1b0620521a1c9680e54df73 and 28c0ee84f1387ab5d0... Read more
Affected Products : asterixdb- Published: Mar. 01, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2020-9478
An issue was discovered in Rubrik 5.0.3-2296. An OS command injection vulnerability allows an authenticated attacker to remotely execute arbitrary code on Rubrik-managed systems.... Read more
Affected Products : cdm- Published: Apr. 13, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-9477
An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices. A vulnerability in the authentication functionality in the web-based interface could allow an unauthenticated remote attacker to capture packets at the time of authentication and gain acces... Read more
- Published: Mar. 04, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9476
ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login page and performing base64 decoding.... Read more
- Published: Mar. 04, 2020
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2020-9475
The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 allows local privilege escalation via a race condition in logrotate. By using an exploit chain, an attacker with access to the network can get root access on the gateway.... Read more
- Published: May. 07, 2020
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2020-9474
The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 allows remote code execution via the backup functionality in the web frontend. By using an exploit chain, an attacker with access to the network can get root access on the gateway.... Read more
- Published: May. 07, 2020
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2020-9473
The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 has a passwordless ftp ssh user. By using an exploit chain, an attacker with access to the network can get root access on the gateway.... Read more
- Published: Apr. 06, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2020-9472
Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package functionality.... Read more
Affected Products : umbraco_cms- Published: Mar. 16, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2020-9471
Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality.... Read more
Affected Products : umbraco_cms- Published: Mar. 16, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-9470
An issue was discovered in Wing FTP Server 6.2.5 before February 2020. Due to insecure permissions when handling session cookies, a local user may view the contents of the session and session_admin directories, which expose active session cookies within t... Read more
Affected Products : wing_ftp_server- Published: Mar. 07, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-9468
The Community plugin 2.9.e-beta for Piwigo allows users to set image information on images in albums for which they do not have permission, by manipulating the image_id parameter.... Read more
Affected Products : piwigo- Published: Mar. 26, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9467
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.... Read more
Affected Products : piwigo- Published: Mar. 26, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2020-9466
The Export Users to CSV plugin through 1.4.2 for WordPress allows CSV Injection.... Read more
Affected Products : export_users_to_csv- Published: Feb. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-9465
An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the user_id field in a cook... Read more
Affected Products : eyesofnetwork- Published: Feb. 28, 2020
- Modified: Nov. 21, 2024