CVE-2020-2000 to CVE-2020-2999
30 CVEs with public proof-of-concept exploits.
- CVE-2020-20211 PoCKEVPAN-OS: Authentication Bypass in SAML Authentication
- CVE-2020-20231 PoCKata Containers - Containers have access to the guest root filesystem device
- CVE-2020-20341 PoCPAN-OS: OS command injection vulnerability in GlobalProtect portal
- CVE-2020-20361 PoCPAN-OS: Reflected Cross-Site Scripting (XSS) vulnerability in management web interface
- CVE-2020-20385 PoCsPAN-OS: OS command injection vulnerability in the management web interface
- CVE-2020-20963 PoCsJenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS…
- CVE-2020-21031 PoCJenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.
- CVE-2020-21401 PoCJenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a…
- CVE-2020-21991 PoCJenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier does not escape the error message for the repository URL field form…
- CVE-2020-22293 PoCsJenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site…
- CVE-2020-22302 PoCsJenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored…
- CVE-2020-22312 PoCsJenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds…
- CVE-2020-22611 PoCJenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Configure permission to…
- CVE-2020-25091 PoCKEVCommand Injection Vulnerability in QTS and QuTS hero
- CVE-2020-25461 PoCVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Application Container - JavaEE). Supported…
- CVE-2020-255118 PoCsKEVVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that…
- CVE-2020-255517 PoCsKEVVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions…
- CVE-2020-26551 PoCVulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.5 and…
- CVE-2020-26561 PoCVulnerability in the Oracle Solaris product of Oracle Systems (component: X Window System). Supported versions that are affected are 10…
- CVE-2020-26962 PoCsVulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). The supported version that is…
- CVE-2020-27332 PoCsVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics). The supported…
- CVE-2020-27711 PoCVulnerability in the Oracle Solaris product of Oracle Systems (component: Whodo). Supported versions that are affected are 10 and 11.…
- CVE-2020-28511 PoCVulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). Supported versions that are…
- CVE-2020-28531 PoCVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected…
- CVE-2020-288315 PoCsKEVVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected…
- CVE-2020-28842 PoCsVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected…
- CVE-2020-29442 PoCsVulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). Supported versions that are…
- CVE-2020-29501 PoCVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web…
- CVE-2020-29691 PoCVulnerability in the Data Pump component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1,…
- CVE-2020-29781 PoCVulnerability in the Oracle Database - Enterprise Edition component of Oracle Database Server. Supported versions that are affected are…