|
CVE-2017-15681
|
Critical
|
2020-11-27
|
Protected by RASP
|
No public exploit
|
In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE.
|
|
CVE-2020-13942
|
Critical
|
2020-11-24
|
Mitigation candidate
|
Working exploit published
|
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the input. It is highly recommended to upgrade to the latest available version of the 1.5.x release to fix this problem.
|
|
CVE-2020-7774
|
Critical
|
2020-11-17
|
No exploit published
|
Forecast only
|
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
|
|
CVE-2020-17510
|
Critical
|
2020-11-05
|
No exploit published
|
No public exploit
|
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
|
|
CVE-2020-2301
|
Critical
|
2020-11-04
|
No exploit published
|
No public exploit
|
Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a successful authentication of that user is still in the optional cache when using Windows/ADSI mode.
|
|
CVE-2020-2300
|
Critical
|
2020-11-04
|
No exploit published
|
No public exploit
|
Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log in to Jenkins as any user depending on the configuration of the Active Directory server.
|
|
CVE-2020-2299
|
Critical
|
2020-11-04
|
No exploit published
|
No public exploit
|
Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as the password.
|
|
CVE-2020-14750
|
Critical
|
2020-11-02
|
Protected by RASP
|
Exploited in the wild
|
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|