Show filters
172 Total Results
Displaying 71-80 of 172
Sort by:
Attacker Value
Unknown

CVE-2020-14523

Disclosure Date: July 30, 2020 (last updated February 23, 2025)
Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.
Attacker Value
Unknown

CVE-2020-14521

Disclosure Date: July 30, 2020 (last updated February 23, 2025)
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.
Attacker Value
Unknown

CVE-2020-9524

Disclosure Date: May 18, 2020 (last updated February 21, 2025)
Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Update 8. The vulnerability could allow an attacker to trigger administrative actions when an administrator viewed malicious data left by the attacker (stored XSS) or followed a malicious link (reflected XSS).
Attacker Value
Unknown

CVE-2020-10683

Disclosure Date: May 01, 2020 (last updated February 21, 2025)
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
Attacker Value
Unknown

CVE-2020-9523

Disclosure Date: April 17, 2020 (last updated February 21, 2025)
Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patch Update 16, and version 5.0 Patch Update 6. The vulnerability could allow an attacker to transmit hashed credentials for the user account running the Micro Focus Directory Server (MFDS) to an arbitrary site, compromising that account's security.
Attacker Value
Unknown

CVE-2020-11658

Disclosure Date: April 15, 2020 (last updated February 21, 2025)
CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.
Attacker Value
Unknown

CVE-2020-11659

Disclosure Date: April 15, 2020 (last updated February 21, 2025)
CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to perform a restricted user administration action.
Attacker Value
Unknown

CVE-2020-11660

Disclosure Date: April 15, 2020 (last updated November 27, 2024)
CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view restricted sensitive information.
Attacker Value
Unknown

CVE-2020-11666

Disclosure Date: April 15, 2020 (last updated November 27, 2024)
CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows malicious users to elevate privileges.
Attacker Value
Unknown

CVE-2020-11663

Disclosure Date: April 15, 2020 (last updated February 21, 2025)
CA API Developer Portal 4.3.1 and earlier handles 404 requests in an insecure manner, which allows attackers to perform open redirect attacks.