CVE-2020-13956
- EPSS 0.51%
- Veröffentlicht 02.12.2020 17:15:14
- Zuletzt bearbeitet 01.12.2025 16:15:48
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
CVE-2020-5421
- EPSS 63.83%
- Veröffentlicht 19.09.2020 04:15:11
- Zuletzt bearbeitet 21.11.2024 05:34:08
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jses...
CVE-2020-7712
- EPSS 0.39%
- Veröffentlicht 30.08.2020 08:15:11
- Zuletzt bearbeitet 21.11.2024 05:37:39
This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.
CVE-2020-14536
- EPSS 1.46%
- Veröffentlicht 15.07.2020 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:03:29
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Workbench). Supported versions that are affected are 11.0, 11.1, 11.2 and prior to 11.3.1. Difficult to exploit vulnerabili...
CVE-2020-13935
- EPSS 91.75%
- Veröffentlicht 14.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:02:10
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with inv...
CVE-2019-17573
- EPSS 15.54%
- Veröffentlicht 16.01.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:33
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into ...
CVE-2019-12423
- EPSS 1.16%
- Veröffentlicht 16.01.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:48
Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the service obtains the public key from...
CVE-2020-2604
- EPSS 1.45%
- Veröffentlicht 15.01.2020 17:15:20
- Zuletzt bearbeitet 21.11.2024 05:25:42
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows...
CVE-2019-10219
- EPSS 1.67%
- Veröffentlicht 08.11.2019 15:15:11
- Zuletzt bearbeitet 07.07.2025 14:15:21
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
CVE-2019-12419
- EPSS 18%
- Veröffentlicht 06.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:48
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is...