CVE-2020-4000 to CVE-2020-4999
29 CVEs with public proof-of-concept exploits.
- CVE-2020-40061 PoCKEVVMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection…
- CVE-2020-40381 PoCReflected XSS in GraphQL Playground
- CVE-2020-40402 PoCsCSRF issue on preview pages in Bolt CMS
- CVE-2020-40411 PoCThe filename of uploaded files vulnerable to stored XSS in Bolt CMS
- CVE-2020-40461 PoCAuthenticated XSS through embed block in WordPress
- CVE-2020-40471 PoCAuthenticated XSS via media attachment page in WordPress
- CVE-2020-40481 PoCOpen redirect in wp_validate_redirect() in WordPress
- CVE-2020-40491 PoCAuthenticated self-XSS via theme uploads in WordPress
- CVE-2020-40501 PoCset-screen-option filter misuse by plugins leading to privilege escalation in WordPress
- CVE-2020-40511 PoCXSS in Dijit Editor's LinkDialog plugin
- CVE-2020-40591 PoCCommand Injection in mversion
- CVE-2020-40661 PoCCommand Injection in Limdu trainBatch function
- CVE-2020-42691 PoCIBM QRadar 7.3.0 to 7.3.3 Patch 2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own…
- CVE-2020-42701 PoCIBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a local user to gain escalated privileges due to weak file permissions. IBM X-ForceID: 175846.
- CVE-2020-42711 PoCIBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to send a specially crafted command which would be executed as a lower…
- CVE-2020-42721 PoCIBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to include arbitrary files. A remote attacker could send a…
- CVE-2020-42741 PoCIBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to access data and perform unauthorized actions due to inadequate…
- CVE-2020-42761 PoCIBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using…
- CVE-2020-42802 PoCsIBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization…
- CVE-2020-42941 PoCIBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to Server Side Request Forgery (SSRF). This may allow an authenticated attacker to send…
- CVE-2020-44272 PoCsKEVIBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when…
- CVE-2020-44281 PoCKEVIBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the…
- CVE-2020-44292 PoCsIBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A…
- CVE-2020-44301 PoCKEVIBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An…
- CVE-2020-44501 PoCIBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a…
- CVE-2020-44633 PoCsIBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A…
- CVE-2020-44641 PoCIBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system…
- CVE-2020-47571 PoCIBM FileNet Content Manager and IBM Content Navigator 3.0.CD is vulnerable to stored cross-site scripting. This vulnerability allows users…
- CVE-2020-48541 PoCIBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses…