Show filters
402 Total Results
Displaying 141-150 of 402
Sort by:
Attacker Value
Unknown

CVE-2020-8031

Disclosure Date: February 01, 2021 (last updated February 22, 2025)
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Open Build Service allows remote attackers to store JS code in markdown that is not properly escaped, impacting confidentiality and integrity. This issue affects: Open Build Service versions prior to 2.10.8.
Attacker Value
Unknown

CVE-2021-22697

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a use-after-free condition which could result in remote code execution when a malicious SSD file is uploaded and improperly parsed.
Attacker Value
Unknown

CVE-2021-22698

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a stack-based buffer overflow to occur which could result in remote code execution when a malicious SSD file is uploaded and improperly parsed.
Attacker Value
Unknown

CVE-2020-2244

Disclosure Date: September 01, 2020 (last updated February 22, 2025)
Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to provide console output for builds used to test build log indications.
Attacker Value
Unknown

CVE-2020-2236

Disclosure Date: August 12, 2020 (last updated February 21, 2025)
Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Run/Update permission.
Attacker Value
Unknown

CVE-2019-14900

Disclosure Date: July 06, 2020 (last updated February 21, 2025)
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.
Attacker Value
Unknown

CVE-2020-8021

Disclosure Date: May 19, 2020 (last updated February 21, 2025)
a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package where the sourceaccess/access is disabled This issue affects: Open Build Service versions prior to 2.10.5.
Attacker Value
Unknown

CVE-2020-8020

Disclosure Date: May 13, 2020 (last updated February 21, 2025)
A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attackers to store arbitrary JS code to cause XSS. This issue affects: openSUSE open-build-service versions prior to 7cc32c8e2ff7290698e101d9a80a9dc29a5500fb.
Attacker Value
Unknown

CVE-2018-12475

Disclosure Date: May 11, 2020 (last updated February 22, 2025)
A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUSE Open Build Service allows authenticated users to generate HTTP request against internal networks and potentially downloading data that is exposed there. This issue affects: openSUSE Open Build Service .
Attacker Value
Unknown

CVE-2020-9375

Disclosure Date: March 25, 2020 (last updated February 21, 2025)
TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header containing an unexpected Referer field.