CVE-2020-24977
- EPSS 3.77%
- Veröffentlicht 04.09.2020 00:15:10
- Zuletzt bearbeitet 21.11.2024 05:16:15
GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.
CVE-2020-7016
- EPSS 1.09%
- Veröffentlicht 27.07.2020 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:36:29
Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.
CVE-2020-7017
- EPSS 1.22%
- Veröffentlicht 27.07.2020 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:36:30
In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of...
CVE-2020-14627
- EPSS 0.98%
- Veröffentlicht 15.07.2020 18:15:27
- Zuletzt bearbeitet 21.11.2024 05:03:43
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access...
CVE-2020-14600
- EPSS 1.09%
- Veröffentlicht 15.07.2020 18:15:25
- Zuletzt bearbeitet 21.11.2024 05:03:39
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network acces...
CVE-2020-14592
- EPSS 0.96%
- Veröffentlicht 15.07.2020 18:15:24
- Zuletzt bearbeitet 21.11.2024 05:03:37
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Rich Text Editor). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with net...
- EPSS 0.86%
- Veröffentlicht 15.07.2020 18:15:22
- Zuletzt bearbeitet 21.11.2024 05:03:33
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Environment Mgmt Console). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows high privileged attacker ...
CVE-2020-14558
- EPSS 1.38%
- Veröffentlicht 15.07.2020 18:15:20
- Zuletzt bearbeitet 21.11.2024 05:03:32
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network acces...
CVE-2020-8203
- EPSS 5.21%
- Veröffentlicht 15.07.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:38:29
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
CVE-2020-7656
- EPSS 6.27%
- Veröffentlicht 19.05.2020 21:15:10
- Zuletzt bearbeitet 21.11.2024 05:37:33
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be...