|
CVE-2020-13951
|
High
|
2020-09-30
|
Mitigation candidate
|
Working exploit published
|
Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.
|
|
CVE-2020-5421
|
Medium
|
2020-09-19
|
No exploit published
|
No public exploit
|
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
|
|
CVE-2020-24750
|
High
|
2020-09-17
|
Protected by RASP
|
No public exploit
|
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
|
|
CVE-2019-0230
|
Critical
|
2020-09-14
|
Protected by RASP
|
Working exploit published
|
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
|
|
CVE-2020-23814
|
Medium
|
2020-09-03
|
Mitigation candidate
|
Working exploit published
|
Multiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) AppName and (2)AddressList parameter in JobGroupController.java file.
|