Search

Search Results (357821 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-16267 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 8.8 High
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.
CVE-2020-16266 1 Mantisbt 1 Mantisbt 2024-11-21 5.4 Medium
An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attacker to inject arbitrary HTML into the page by saving it into a text Custom Field, leading to possible code execution in the browser of any user subsequently viewing the issue (if CSP settings allow it).
CVE-2020-16263 1 Winstonprivacy 2 Winston, Winston Firmware 2024-11-21 9.1 Critical
Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewed by arbitrary origins.
CVE-2020-16262 1 Winstonprivacy 2 Winston, Winston Firmware 2024-11-21 7.8 High
Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation.
CVE-2020-16261 1 Winstonprivacy 2 Winston, Winston Firmware 2024-11-21 6.8 Medium
Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access.
CVE-2020-16260 1 Winstonprivacy 2 Winston, Winston Firmware 2024-11-21 7.5 High
Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote exploitation.
CVE-2020-16259 1 Winstonprivacy 2 Winston, Winston Firmware 2024-11-21 9.8 Critical
Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents and is not announced to the user.
CVE-2020-16258 1 Winstonprivacy 2 Winston, Winston Firmware 2024-11-21 7.1 High
Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials.
CVE-2020-16257 1 Winstonprivacy 2 Winston, Winston Firmware 2024-11-21 9.8 Critical
Winston 1.5.4 devices are vulnerable to command injection via the API.
CVE-2020-16256 1 Winstonprivacy 2 Winston, Winston Firmware 2024-11-21 8.8 High
The API on Winston 1.5.4 devices is vulnerable to CSRF.
CVE-2020-16255 1 Owncloud 1 Owncloud 2024-11-21 6.1 Medium
ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'
CVE-2020-16254 1 Chartkick Project 1 Chartkick 2024-11-21 6.1 Medium
The Chartkick gem through 3.3.2 for Ruby allows Cascading Style Sheets (CSS) Injection (without attribute).
CVE-2020-16253 1 Pghero Project 1 Pghero 2024-11-21 8.1 High
The PgHero gem through 2.6.0 for Ruby allows CSRF.
CVE-2020-16252 1 Field Test Project 1 Field Test 2024-11-21 4.3 Medium
The Field Test gem 0.2.0 through 0.3.2 for Ruby allows CSRF.
CVE-2020-16251 2 Hashicorp, Redhat 3 Vault, Openshift, Openshift Data Foundation 2024-11-21 8.2 High
HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1.
CVE-2020-16250 2 Hashicorp, Redhat 3 Vault, Openshift, Openshift Data Foundation 2024-11-21 8.2 High
HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1..
CVE-2020-16248 1 Prometheus 1 Blackbox Exporter 2024-11-21 5.8 Medium
Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability
CVE-2020-16246 1 Ge 4 S2020, S2020 Firmware, S2024 and 1 more 2024-11-21 6.1 Medium
The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow attackers to trick users into following a link or navigating to a page that posts a malicious JavaScript statement to the vulnerable site, causing the malicious JavaScript to be rendered by the site and executed by the victim client.
CVE-2020-16245 1 Advantech 1 Iview 2024-11-21 9.8 Critical
Advantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.
CVE-2020-16244 1 Ge 1 Asset Performance Management Classic 2024-11-21 7.2 High
GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, making it possible to decrypt passwords. This design flaw, along with the IDOR vulnerability, puts the entire platform at high risk because an authenticated user can retrieve all user account data and then retrieve the actual passwords.