VRT 391,810 CVEs tracked · 15,472 in RASP scope · data as of 47 minutes ago
Reset
More filters (2)
Columns
Published from 2020-11-01Published to 2020-11-30
Overview 8 matches, all in RASP scope · 2 protected · 1 KEV · 2 public PoC · 1 CISA SSVC · 3 EPSS ≥ 0.5 · 0 disputed
8matches, all in RASP scope 2protected25.0% 1KEV12.5% 2public PoC25.0% 1CISA SSVC12.5% 3EPSS ≥ 0.537.5% 0disputed0.0%
Critical 8 100.0% High 0 0.0% Medium 0 0.0% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 2 25.0% Rule in development 0 0.0% Mitigation candidate 1 12.5% No exploit published 5 62.5% No fix identified 0 0.0% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 2 25.0% not blocked 6 75.0% not established 0 0.0% unrecorded 0 0.0%
split by peak 8 / month
Unknown: 0None: 0Low: 0Medium: 0High: 0Critical: 8 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 0No fix identified: 0No exploit published: 5Mitigation candidate: 1Rule in development: 0Protected by RASP: 2 unrecorded: 0not established: 0not blocked: 6blocked by ARMR today: 2 No public exploit: 5Forecast only: 1Proof of concept only: 0Working exploit published: 1Exploited in the wild: 1 November 2020: 8 CVEs
Nov 20
8 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2017-15681 Critical 2020-11-27 Protected by RASP No public exploit In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE.
CVE-2020-13942 Critical 2020-11-24 Mitigation candidate Working exploit published It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the input. It is highly recommended to upgrade to the latest available version of the 1.5.x release to fix this problem.
CVE-2020-7774 Critical 2020-11-17 No exploit published Forecast only The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
CVE-2020-17510 Critical 2020-11-05 No exploit published No public exploit Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
CVE-2020-2301 Critical 2020-11-04 No exploit published No public exploit Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a successful authentication of that user is still in the optional cache when using Windows/ADSI mode.
CVE-2020-2300 Critical 2020-11-04 No exploit published No public exploit Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log in to Jenkins as any user depending on the configuration of the Active Directory server.
CVE-2020-2299 Critical 2020-11-04 No exploit published No public exploit Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as the password.
CVE-2020-14750 Critical 2020-11-02 Protected by RASP Exploited in the wild Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).