Show filters
542 Total Results
Displaying 261-270 of 542
Sort by:
Attacker Value
Unknown

CVE-2020-15143

Disclosure Date: August 20, 2020 (last updated February 22, 2025)
In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, rrequest parameters injected inside an expression evaluated by `symfony/expression-language` package haven't been sanitized properly. This allows the attacker to access any public service by manipulating that request parameter, allowing for Remote Code Execution. This issue has been patched for versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4. Versions prior to 1.3 were not patched.
Attacker Value
Unknown

CVE-2019-19704

Disclosure Date: August 08, 2020 (last updated November 28, 2024)
In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm.
Attacker Value
Unknown

CVE-2020-2213

Disclosure Date: July 02, 2020 (last updated February 21, 2025)
Jenkins White Source Plugin 19.1.1 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission (config.xml), or access to the master file system.
Attacker Value
Unknown

CVE-2020-5304

Disclosure Date: June 08, 2020 (last updated February 21, 2025)
The dashboard in WhiteSource Application Vulnerability Management (AVM) before version 20.4.1 allows Log Injection via a %0A%0D substring in the idp parameter to the /saml/login URI. This closes the current log and creates a new log with one line of data. The attacker can also insert malicious data and false entries.
Attacker Value
Unknown

CVE-2020-8151

Disclosure Date: May 12, 2020 (last updated February 21, 2025)
There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information.
Attacker Value
Unknown

CVE-2020-2189

Disclosure Date: May 06, 2020 (last updated February 21, 2025)
Jenkins SCM Filter Jervis Plugin 0.2.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
Attacker Value
Unknown

CVE-2020-12283

Disclosure Date: April 30, 2020 (last updated February 21, 2025)
Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/redirect.go, such as for the //foo//example.com substring.
Attacker Value
Unknown

CVE-2020-12242

Disclosure Date: April 27, 2020 (last updated February 21, 2025)
Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a different user account.
Attacker Value
Unknown

CVE-2020-6996

Disclosure Date: April 15, 2020 (last updated February 21, 2025)
Triangle MicroWorks DNP3 Outstation LibrariesDNP3 Outstation .NET Protocol components and DNP3 Outstation ANSI C source code libraries are affected:3.16.00 through 3.25.01. A specially crafted message may cause a stack-based buffer overflow. Authentication is not required to exploit this vulnerability.
Attacker Value
Unknown

CVE-2020-2956

Disclosure Date: April 15, 2020 (last updated November 27, 2024)
Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Human Resources accessible data as well as unauthorized access to critical data or complete access to all Oracle Human Resources accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).