Show filters
104 Total Results
Displaying 61-70 of 104
Sort by:
Attacker Value
Unknown
CVE-2020-11994
Disclosure Date: July 08, 2020 (last updated February 21, 2025)
Server-Side Template Injection and arbitrary file disclosure on Camel templating components
0
Attacker Value
Unknown
CVE-2020-1941
Disclosure Date: May 14, 2020 (last updated February 21, 2025)
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
0
Attacker Value
Unknown
CVE-2020-1945
Disclosure Date: May 14, 2020 (last updated February 21, 2025)
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.
0
Attacker Value
Unknown
CVE-2020-11415
Disclosure Date: April 27, 2020 (last updated February 21, 2025)
An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.
0
Attacker Value
Unknown
CVE-2020-11753
Disclosure Date: April 20, 2020 (last updated February 21, 2025)
An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default (making this not exploitable).
0
Attacker Value
Unknown
CVE-2020-5315
Disclosure Date: January 14, 2020 (last updated February 23, 2025)
Dell EMC Repository Manager (DRM) version 3.2 contains a plain-text password storage vulnerability. Proxy server user password is stored in a plain text in a local database. A local authenticated malicious user with access to the local file system may use the exposed password to access the with privileges of the compromised user.
0
Attacker Value
Unknown
CVE-2019-10219
Disclosure Date: November 08, 2019 (last updated November 08, 2023)
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
0
Attacker Value
Unknown
CVE-2019-12415
Disclosure Date: October 23, 2019 (last updated November 08, 2023)
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
0
Attacker Value
Unknown
CVE-2019-16530
Disclosure Date: October 21, 2019 (last updated November 27, 2024)
Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.
0
Attacker Value
Unknown
CVE-2019-15893
Disclosure Date: October 16, 2019 (last updated November 27, 2024)
Sonatype Nexus Repository Manager 2.x before 2.14.15 allows Remote Code Execution.
0