Show filters
188 Total Results
Displaying 101-110 of 188
Sort by:
Attacker Value
Unknown
CVE-2020-25179
Disclosure Date: December 14, 2020 (last updated February 22, 2025)
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
0
Attacker Value
Unknown
CVE-2020-25175
Disclosure Date: December 14, 2020 (last updated February 22, 2025)
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
0
Attacker Value
Unknown
CVE-2020-8567
Disclosure Date: November 16, 2020 (last updated February 22, 2025)
Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/lib/kubelet/pods.
0
Attacker Value
Unknown
CVE-2020-2313
Disclosure Date: November 04, 2020 (last updated October 26, 2023)
A missing permission check in Jenkins Azure Key Vault Plugin 2.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
0
Attacker Value
Unknown
CVE-2020-14736
Disclosure Date: October 21, 2020 (last updated November 28, 2024)
Vulnerability in the Database Vault component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create Public Synonym privilege with network access via Oracle Net to compromise Database Vault. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Database Vault accessible data as well as unauthorized read access to a subset of Database Vault accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).
0
Attacker Value
Unknown
CVE-2020-26124
Disclosure Date: October 02, 2020 (last updated February 22, 2025)
openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, because json_encode_safe is not used in config/databasebackend.inc. Successful exploitation allows arbitrary command execution on the underlying operating system as root.
0
Attacker Value
Unknown
CVE-2020-25816
Disclosure Date: September 30, 2020 (last updated November 28, 2024)
HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their TTL because expiration time was not scheduled correctly. Fixed in 1.4.7 and 1.5.4.
0
Attacker Value
Unknown
CVE-2020-4607
Disclosure Date: September 28, 2020 (last updated February 22, 2025)
IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security restrictions due to improper input validation. IBM X-Force ID: 184884.
0
Attacker Value
Unknown
CVE-2020-16250
Disclosure Date: August 26, 2020 (last updated February 22, 2025)
HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1..
0
Attacker Value
Unknown
CVE-2020-16251
Disclosure Date: August 26, 2020 (last updated February 22, 2025)
HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1.
0