Show filters
68 Total Results
Displaying 1-10 of 68
Sort by:
Attacker Value
High

CVE-2020-3956: VMware Cloud Director Code Injection Vulnerability

Disclosure Date: May 20, 2020 (last updated February 21, 2025)
VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly handle input leading to a code injection vulnerability. An authenticated actor may be able to send malicious traffic to VMware Cloud Director which may lead to arbitrary remote code execution. This vulnerability can be exploited through the HTML5- and Flex-based UIs, the API Explorer interface and API access.
Attacker Value
Very High

CVE-2020-17530

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
Attacker Value
Unknown

CVE-2020-10199

Disclosure Date: April 01, 2020 (last updated February 21, 2025)
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
Attacker Value
Unknown

CVE-2020-7162

Disclosure Date: October 19, 2020 (last updated February 22, 2025)
A operatorgroupselectcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
Attacker Value
Unknown

CVE-2020-7165

Disclosure Date: October 19, 2020 (last updated February 22, 2025)
A iccselectcommand expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
Attacker Value
Unknown

CVE-2020-7149

Disclosure Date: October 19, 2020 (last updated February 22, 2025)
A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
Attacker Value
Unknown

CVE-2020-7157

Disclosure Date: October 19, 2020 (last updated February 22, 2025)
A selviewnavcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
Attacker Value
Unknown

CVE-2020-7195

Disclosure Date: October 19, 2020 (last updated February 22, 2025)
A iccselectrules expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
Attacker Value
Unknown

CVE-2020-7171

Disclosure Date: October 19, 2020 (last updated February 22, 2025)
A guidatadetail expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
Attacker Value
Unknown

CVE-2020-7172

Disclosure Date: October 19, 2020 (last updated February 22, 2025)
A templateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).