Show filters
440 Total Results
Displaying 221-230 of 440
Sort by:
Attacker Value
Unknown
CVE-2020-4452
Disclosure Date: June 26, 2020 (last updated February 21, 2025)
IBM API Connect V2018.4.1.0 through 2018.4.1.11 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 181324.
0
Attacker Value
Unknown
CVE-2020-13700
Disclosure Date: June 24, 2020 (last updated February 21, 2025)
An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive information in the wp_options table, such as the login and pass values.
0
Attacker Value
Unknown
CVE-2020-12021
Disclosure Date: June 23, 2020 (last updated February 21, 2025)
In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cross-site scripting attack, which may allow an attacker to remotely execute arbitrary code.
0
Attacker Value
Unknown
CVE-2020-14159
Disclosure Date: June 15, 2020 (last updated February 21, 2025)
By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications within an individual Automate instance by triggering an SQL injection vulnerability in /LabTech/agent.aspx. This affects versions before 2019.12.337, 2020 before 2020.1.53, 2020.2 before 2020.2.85, 2020.3 before 2020.3.114, 2020.4 before 2020.4.143, and 2020.5 before 2020.5.178.
0
Attacker Value
Unknown
CVE-2020-4251
Disclosure Date: June 11, 2020 (last updated February 21, 2025)
IBM API Connect 5.0.0.0 through 5.0.8.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 175489.
0
Attacker Value
Unknown
CVE-2020-13883
Disclosure Date: June 06, 2020 (last updated February 21, 2025)
In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle.
0
Attacker Value
Unknown
CVE-2020-2193
Disclosure Date: June 03, 2020 (last updated February 21, 2025)
Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the parser identifier when rendering charts, resulting in a stored cross-site scripting vulnerability.
0
Attacker Value
Unknown
CVE-2020-2194
Disclosure Date: June 03, 2020 (last updated February 21, 2025)
Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the display name of the builds in the trend chart, resulting in a stored cross-site scripting vulnerability.
0
Attacker Value
Unknown
CVE-2020-13226
Disclosure Date: May 20, 2020 (last updated February 21, 2025)
WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet.
0
Attacker Value
Unknown
CVE-2020-4346
Disclosure Date: May 11, 2020 (last updated November 27, 2024)
IBM API Connect's V2018.4.1.0 through 2018.4.1.10 management server has an unsecured api which can be exploited by an unauthenticated attacker to obtain sensitive information. IBM X-Force ID: 178322.
0