Show filters
440 Total Results
Displaying 231-240 of 440
Sort by:
Attacker Value
Unknown

CVE-2020-4195

Disclosure Date: May 11, 2020 (last updated February 21, 2025)
IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 174859.
Attacker Value
Unknown

CVE-2020-12719

Disclosure Date: May 08, 2020 (last updated February 21, 2025)
XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, API Microgateway 2.2.0, Enterprise Integrator 6.4.0 and earlier, IS as Key Manager 5.9.0 and earlier, Identity Server 5.9.0 and earlier, and Identity Server Analytics 5.6.0 and earlier.
Attacker Value
Unknown

CVE-2020-12642

Disclosure Date: May 04, 2020 (last updated February 21, 2025)
An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resultant secrets disclosure and SSRF, via JUnit XML launch import.
Attacker Value
Unknown

CVE-2020-10683

Disclosure Date: May 01, 2020 (last updated February 21, 2025)
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
Attacker Value
Unknown

CVE-2020-11015

Disclosure Date: April 30, 2020 (last updated February 21, 2025)
A vulnerability has been disclosed in thinx-device-api IoT Device Management Server before version 2.5.0. Device MAC address can be spoofed. This means initial registration requests without UDID and spoofed MAC address may pass to create new UDID with same MAC address. Full impact needs to be reviewed further. Applies to all (mostly ESP8266/ESP32) users. This has been fixed in firmware version 2.5.0.
Attacker Value
Unknown

CVE-2020-11883

Disclosure Date: April 17, 2020 (last updated February 21, 2025)
In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpected HTTP requests lead to an exception that discloses the error stack trace, with absolute file paths and Node.js module names.
Attacker Value
Unknown

CVE-2020-11658

Disclosure Date: April 15, 2020 (last updated February 21, 2025)
CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.
Attacker Value
Unknown

CVE-2020-11659

Disclosure Date: April 15, 2020 (last updated February 21, 2025)
CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to perform a restricted user administration action.
Attacker Value
Unknown

CVE-2020-11660

Disclosure Date: April 15, 2020 (last updated November 27, 2024)
CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view restricted sensitive information.
Attacker Value
Unknown

CVE-2020-11666

Disclosure Date: April 15, 2020 (last updated November 27, 2024)
CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows malicious users to elevate privileges.