Show filters
23 Total Results
Displaying 1-10 of 23
Sort by:
Attacker Value
Unknown

CVE-2021-20405

Disclosure Date: February 10, 2021 (last updated February 22, 2025)
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to perform unauthorized activities due to improper encoding of output. IBM X-Force ID: 196183.
Attacker Value
Unknown

CVE-2020-36173

Disclosure Date: January 06, 2021 (last updated February 22, 2025)
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
Attacker Value
Unknown

CVE-2020-13654

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
XWiki Platform before 12.8 mishandles escaping in the property displayer.
Attacker Value
Unknown

CVE-2020-29023

Disclosure Date: December 18, 2020 (last updated February 22, 2025)
Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim's computer when opened in a spreadsheet program (like Excel). This issue affects: Secomea GateManager all versions prior to 9.3.
Attacker Value
Unknown

CVE-2020-28954

Disclosure Date: November 19, 2020 (last updated February 22, 2025)
web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name.
Attacker Value
Unknown

CVE-2020-26226

Disclosure Date: November 18, 2020 (last updated February 22, 2025)
In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` can be accidentally disclosed if they contain characters that become encoded when included in a URL. Secrets that do not contain characters that become encoded when included in a URL are already masked properly. The issue is fixed in version 17.2.3.
Attacker Value
Unknown

CVE-2020-25646

Disclosure Date: October 29, 2020 (last updated February 22, 2025)
A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This directly impacts confidentiality
Attacker Value
Unknown

CVE-2020-27604

Disclosure Date: October 21, 2020 (last updated February 22, 2025)
BigBlueButton before 2.3 does not implement LibreOffice sandboxing. This might make it easier for remote authenticated users to read the API shared secret in the bigbluebutton.properties file. With the API shared secret, an attacker can (for example) use api/join to join an arbitrary meeting regardless of its guestPolicy setting.
Attacker Value
Unknown

CVE-2020-9862

Disclosure Date: October 16, 2020 (last updated February 22, 2025)
A command injection issue existed in Web Inspector. This issue was addressed with improved escaping. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Copying a URL from Web Inspector may lead to command injection.
Attacker Value
Unknown

CVE-2019-4326

Disclosure Date: October 06, 2020 (last updated February 22, 2025)
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."