Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In August 2020
Laborator Neon dashboard v3 is affected by stored Cross Site Scripting (XSS) via the chat tab.
CVSS Score
5.4
EPSS Score
0.002
Published
2020-08-27
eonweb in EyesOfNetwork before 5.3-7 does not properly escape the username on the /module/admin_logs page, which might allow pre-authentication stored XSS during login/logout logs recording.
CVSS Score
6.1
EPSS Score
0.004
Published
2020-08-27
An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an attacker-controlled server if the victim submits a crafted Try It request, aka Session Hijacking. This affects API Manager 2.2.0, API Manager Analytics 2.2.0, API Microgateway 2.2.0, Data Analytics Server 3.2.0, Enterprise Integrator through 6.6.0, IS as Key Manager 5.5.0, Identity Server 5.5.0 and 5.8.0, Identity Server Analytics 5.5.0, and IoT Server 3.3.0 and 3.3.1.
CVSS Score
8.8
EPSS Score
0.004
Published
2020-08-27
An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager 2.2.0, API Manager Analytics 2.2.0, API Microgateway 2.2.0, Data Analytics Server 3.2.0, Enterprise Integrator through 6.6.0, IS as Key Manager 5.5.0, Identity Server 5.5.0 and 5.8.0, Identity Server Analytics 5.5.0, and IoT Server 3.3.0 and 3.3.1.
CVSS Score
6.1
EPSS Score
0.002
Published
2020-08-27
An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an attacker-controlled server if the victim submits a crafted Try It request, aka Session Hijacking. This affects API Manager through 3.1.0, API Manager Analytics 2.5.0, IS as Key Manager through 5.10.0, Identity Server through 5.10.0, Identity Server Analytics through 5.6.0, and IoT Server 3.1.0.
CVSS Score
8.8
EPSS Score
0.004
Published
2020-08-27
An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager through 3.1.0, API Manager Analytics 2.5.0, IS as Key Manager through 5.10.0, Identity Server through 5.10.0, Identity Server Analytics through 5.6.0, and IoT Server 3.1.0.
CVSS Score
6.1
EPSS Score
0.006
Published
2020-08-27
A vulnerability in the Protocol Independent Multicast (PIM) feature for IPv6 networks (PIM6) of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper error handling when processing inbound PIM6 packets. An attacker could exploit this vulnerability by sending multiple crafted PIM6 packets to an affected device. A successful exploit could allow the attacker to cause the PIM6 application to leak system memory. Over time, this memory leak could cause the PIM6 application to stop processing legitimate PIM6 traffic, leading to a DoS condition on the affected device.
CVSS Score
7.5
EPSS Score
0.013
Published
2020-08-27
oss_write in audio/ossaudio.c in QEMU before 5.0.0 mishandles a buffer position.
CVSS Score
3.3
EPSS Score
0.001
Published
2020-08-27
On Mercedes-Benz C Class AMG Premium Plus c220 BlueTec vehicles, the Bluetooth stack mishandles %x and %c format-string specifiers in a device name in the COMAND infotainment software.
CVSS Score
3.5
EPSS Score
0.001
Published
2020-08-27
13enforme CMS 1.0 has SQL Injection via the 'content.php' id parameter.
CVSS Score
9.8
EPSS Score
0.003
Published
2020-08-27


Contact Us

Shodan ® - All rights reserved