BlackTreeCVE Intelligence
← Back to the CVE catalogue
Full vulnerability report · 2020
CVE-2020-11023High confidence

JQuery Cross-Site Scripting (XSS) Vulnerability

jquery · jQuery

6.9MediumCVSS 3.1
Recommended action
Patch only the product branches with a verified fix

CISA confirms exploitation in the wild and lists 2025-02-13 as the remediation due date. Verified remediation exists for at least one product or source, but 4 structured product or package states remain unresolved. Apply remediation only to the exact product branch confirmed by its source.

Fix availability varies by product
R
Operational reassessment

Published severity in operational context

Open reassessment dashboard →
Published severityMediumOperational priority:Critical, raised 2 bands.upgradedsince 23 Jan 2025

Evidence used

  • CISA confirms exploitation in the wild.
  • A structured source references public exploit or proof-of-concept material.
  • EPSS is 84.89% for the current model date.

Compensating controls

  • Validate the affected product branch and deploy the verified fixed release.
  • Restrict the affected network interface to trusted sources where business-safe.
  • Increase monitoring for the attack path and post-exploitation behaviour described in the report.

Verification

  1. Confirm that the asset runs jquery jQuery and falls inside the recorded affected range.
  2. Verify the installed build against the product-specific fixed version after deployment.
  3. Validate exposure, authentication requirements and compensating controls in the actual environment.
  4. Reopen this reassessment when CVSS, KEV, EPSS, exploit evidence or remediation changes.
Mitigation target: Within 3 daysRemediation target: Within 90 days

This automated reassessment organises public evidence. It does not know asset exposure, business impact or control effectiveness and does not replace CVSS or a human risk decision.

Cross-source reconciliation

Remediation availability differs by product scope

Verified remediation exists for at least one product or source, but 4 structured product or package states remain unresolved. Apply remediation only to the exact product branch confirmed by its source.

Distribution package intelligence

Release-specific package status

Alpine, Debian findings are scoped to the named distribution, release and source package. An absent finding does not mean a package is unaffected.

11 package states
Package result overrides the generic status

BlackTree has verified remediation for at least one product or source, but the relevant distribution still reports no fixed package for 2 affected package states shown here. Treat those rows as affected with no fix until that distribution publishes a fixed version.

Repository candidate not checked

A published vendor fix does not prove that a matching update is enabled and installable on a particular asset. Confirm the local package candidate before scheduling remediation.

Distribution releaseSource packageVendor stateFixed versionEvidence
Alpine v3.23v3.23 · communitycactiVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.2.13-r0Alpine Security Database ↗Source updated 11 Sep 2026
Alpine v3.22v3.22 · communitycactiVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.2.13-r0Alpine Security Database ↗Source updated 11 Sep 2026
Alpine v3.21v3.21 · communitycactiVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.2.13-r0Alpine Security Database ↗Source updated 19 Aug 2026
Debian trixietrixie · sourcenode-jqueryVendor fix publishedDebian records a fixed source-package version for this release.3.5.0+dfsg-2Debian Security Tracker ↗Source updated 5 Oct 2026
Debian trixietrixie · sourcezncAffected, no fix publishedDebian currently tracks this release as open.Not published in this feedDebian Security Tracker ↗Source updated 5 Oct 2026
Debian bookwormbookworm · sourcenode-jqueryVendor fix publishedDebian records a fixed source-package version for this release.3.5.0+dfsg-2Debian Security Tracker ↗Source updated 5 Oct 2026
Debian bookwormbookworm · sourcezncAffected, no fix publishedDebian currently tracks this release as open.Not published in this feedDebian Security Tracker ↗Source updated 5 Oct 2026
Debian forkyforky · sourcenode-jqueryVendor fix publishedDebian records a fixed source-package version for this release.3.5.0+dfsg-2Debian Security Tracker ↗Source updated 5 Oct 2026
Debian forkyforky · sourcezncVendor fix publishedDebian records a fixed source-package version for this release.1.10.3-1Debian Security Tracker ↗Source updated 5 Oct 2026
Debian sidsid · sourcenode-jqueryVendor fix publishedDebian records a fixed source-package version for this release.3.5.0+dfsg-2Debian Security Tracker ↗Source updated 5 Oct 2026
Debian sidsid · sourcezncVendor fix publishedDebian records a fixed source-package version for this release.1.10.3-1Debian Security Tracker ↗Source updated 5 Oct 2026
Open-source package ranges10 source-attributed ranges

These OSV and GitHub advisory ranges apply only to the named package and ecosystem. A listed fixed version is not a universal product patch or proof that an update is installed.

Ecosystem and packageAffected rangeFirst fixed versionEvidence
Mavenorg.webjars.npm:jqueryECOSYSTEM: introduced 1.0.3; fixed 3.5.03.5.0OSV record ↗aggregator derived · 10 Sep 2026
NuGetjQueryECOSYSTEM: introduced 1.0.3; fixed 3.5.03.5.0OSV record ↗aggregator derived · 10 Sep 2026
Packagistcomponents/jqueryECOSYSTEM: introduced 1.0.3; fixed 3.5.03.5.0OSV record ↗aggregator derived · 10 Sep 2026
RubyGemsjquery-railsECOSYSTEM: introduced 0; fixed 4.4.04.4.0OSV record ↗aggregator derived · 10 Sep 2026
composercomponents/jquery>= 1.0.3, < 3.5.03.5.0GitHub advisory ↗upstream repository advisory · 22 Oct 2025
mavenorg.webjars.npm:jquery>= 1.0.3, < 3.5.03.5.0GitHub advisory ↗upstream repository advisory · 22 Oct 2025
npmjquery>= 1.0.3, < 3.5.03.5.0GitHub advisory ↗upstream repository advisory · 22 Oct 2025
npmjquerySEMVER: introduced 1.0.3; fixed 3.5.03.5.0OSV record ↗aggregator derived · 10 Sep 2026
nugetjQuery>= 1.0.3, < 3.5.03.5.0GitHub advisory ↗upstream repository advisory · 22 Oct 2025
rubygemsjquery-rails< 4.4.04.4.0GitHub advisory ↗upstream repository advisory · 22 Oct 2025
Direct vendor intelligence

Authoritative vendor CSAF and VEX advisories

Structured product status and remediation from the issuing vendor. Product-state explanations are always visible; large lists can be searched or downloaded.

2 current
CVE-2020-11023 · CSAF 2.0 · revision 3 · finalRed Hat Product Securityjquery: Untrusted code execution via tag in HTML passed to DOM manipulation methods
169 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • cfme-gemset as a component of CloudForms Management Engine 5
  • cfme-gemset.src as a component of CloudForms Management Engine 5
  • grafana as a component of Red Hat Ceph Storage 3
  • grafana-container as a component of Red Hat Ceph Storage 3
  • grafana.src as a component of Red Hat Ceph Storage 3
  • rhceph/rhceph-4-dashboard-rhel8 as a component of Red Hat Ceph Storage 4
  • compat-gcc-34-c++ as a component of Red Hat Enterprise Linux 6
  • compat-gcc-34-g77 as a component of Red Hat Enterprise Linux 6
  • compat-gcc-34.src as a component of Red Hat Enterprise Linux 6
  • compat-libf2c-34 as a component of Red Hat Enterprise Linux 6
  • compat-libgcc-295 as a component of Red Hat Enterprise Linux 6
  • compat-libgcc-296 as a component of Red Hat Enterprise Linux 6
Summary
A flaw was found in jQuery. HTML containing \ elements from untrusted sources are passed, even after sanitizing, to one of jQuery's DOM manipulation methods, which may execute untrusted code. The highest threat from this vulnerability is to data confidentiality and integrity.
Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
SEVD-2025-189-02 · CSAF 2.0 · revision 1.0.0 · finalSchneider Electric CPCERTSystem Monitor Application in Harmony and Pro-face PS5000 Legacy Industrial PCs
2 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • Schneider Electric System Monitor application installed on Schneider Electric Harmony Industrial PC All Versions
  • Schneider Electric System Monitor application installed on Schneider Electric Pro-face Industrial PC All Versions
Summary
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Remediation
Customer can uninstall System Monitor application using installer available for download here: https://www.se.com/ww/en/product-range/61054- harmony-industrial-pc/#software-and-firmware Please follow the steps described in the guideline attached as a .pdf in the downloaded uninstaller guide.
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Choose official national sources for this report. Each advisory shows its original language. Your selection is remembered on this device and included in shared links.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2020-0387

CISA KEV mirrored by ENISA

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

EUVD state
Present in the current official mapping
Known exploitation
Recorded by ENISA since 23 Jan 2025. Evidence sources: cisa_kev.
ENISA score
6.9 · CVSS 3.1
Advisory evidence
81 linked advisory records
Explicit mitigation evidence

Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.

  • csaf_redhat · RHSA-2021:4142Red Hat Security Advisory: pcs security, bug fix, and enhancement update
  • csaf_redhat · RHSA-2025:1210Red Hat Security Advisory: tbb security update
  • csaf_redhat · RHSA-2025:1249Red Hat Security Advisory: updated discovery container images
  • csaf_redhat · RHSA-2025:1256Red Hat Security Advisory: doxygen security update
  • csaf_redhat · RHSA-2022:7343Red Hat Security Advisory: pcs security update
  • csaf_redhat · RHSA-2025:1601Red Hat Security Advisory: gcc security update
  • csaf_redhat · RHSA-2025:1212Red Hat Security Advisory: tbb security update
  • csaf_redhat · RHSA-2025:1070Red Hat Security Advisory: Red Hat OpenStack Platform 16.2 (python-django20) security update
  • csaf_redhat · RHSA-2023:0553Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.9 Security update
  • csaf_redhat · RHSA-2020:2412Red Hat Security Advisory: OpenShift Container Platform 4.5 container image security update
  • csaf_redhat · RHSA-2020:4211Red Hat Security Advisory: Red Hat AMQ Interconnect 1.9.0 release and security update
  • csaf_redhat · RHSA-2025:1213Red Hat Security Advisory: tbb security update
  • csaf_redhat · RHBA-2025:1079Red Hat Bug Fix Advisory: Red Hat Quay v3.13.4 bug fix release
  • csaf_redhat · RHSA-2023:1044Red Hat Security Advisory: Red Hat Single Sign-On 7.6.2 security update on RHEL 8
  • csaf_redhat · RHSA-2025:1209Red Hat Security Advisory: tbb security update
  • csaf_redhat · RHSA-2025:1303Red Hat Security Advisory: gcc security update
  • csaf_opensuse · openSUSE-SU-2020:1888-1Security update for otrs
  • csaf_redhat · RHSA-2020:5249Red Hat Security Advisory: security update - Red Hat Ansible Tower 3.7.4-1 - RHEL7 Container
  • csaf_redhat · RHSA-2025:1247Red Hat Security Advisory: doxygen security update
  • csaf_redhat · RHBA-2025:1600Red Hat Bug Fix Advisory: Red Hat Quay v3.10.9 bug fix release
  • csaf_redhat · RHSA-2025:1338Red Hat Security Advisory: gcc-toolset-14-gcc security update
  • csaf_redhat · RHSA-2025:1342Red Hat Security Advisory: gcc-toolset-13-gcc security update
  • csaf_redhat · RHBA-2025:1599Red Hat Bug Fix Advisory: Red Hat Quay v3.11.9 bug fix release
  • csaf_redhat · RHSA-2020:5412Red Hat Security Advisory: python-XStatic-jQuery224 security update
  • csaf_redhat · RHSA-2025:1215Red Hat Security Advisory: tbb security update
  • csaf_redhat · RHSA-2025:1580Red Hat Security Advisory: gcc security update
  • csaf_redhat · RHSA-2025:1312Red Hat Security Advisory: gcc security update
  • csaf_redhat · RHSA-2025:1306Red Hat Security Advisory: gcc-toolset-13-gcc security update
  • csaf_redhat · RHSA-2020:3807Red Hat Security Advisory: Red Hat Virtualization security, bug fix, and enhancement update
  • csaf_redhat · RHSA-2025:1515Red Hat Security Advisory: idm:DL1 security update
  • csaf_redhat · RHSA-2025:1315Red Hat Security Advisory: doxygen security update
  • csaf_redhat · RHSA-2025:1185Red Hat Security Advisory: doxygen security update
  • csaf_redhat · RHSA-2020:2813Red Hat Security Advisory: Red Hat Single Sign-On 7.4.1 security update
  • csaf_redhat · RHSA-2025:1514Red Hat Security Advisory: ipa security update
  • csaf_opensuse · openSUSE-SU-2020:1060-1Security update for cacti, cacti-spine
  • csaf_redhat · RHSA-2021:1846Red Hat Security Advisory: idm:DL1 and idm:client security, bug fix, and enhancement update
  • csaf_redhat · RHSA-2023:1045Red Hat Security Advisory: Red Hat Single Sign-On 7.6.2 security update on RHEL 9
  • csaf_redhat · RHSA-2025:1214Red Hat Security Advisory: tbb security update
  • csaf_redhat · RHSA-2025:1305Red Hat Security Advisory: gcc security update
  • csaf_redhat · RHBA-2025:1598Red Hat Bug Fix Advisory: Red Hat Quay v3.12.8 bug fix release
  • csaf_opensuse · openSUSE-SU-2020:1106-1Security update for cacti, cacti-spine
  • csaf_redhat · RHSA-2020:3369Red Hat Security Advisory: Red Hat OpenShift Service Mesh security update
  • csaf_redhat · RHSA-2020:3247Red Hat Security Advisory: RHV Manager (ovirt-engine) 4.4 security, bug fix, and enhancement update
  • csaf_redhat · RHSA-2025:1300Red Hat Security Advisory: gcc-toolset-14-gcc security update
  • csaf_redhat · RHSA-2025:1217Red Hat Security Advisory: tbb security update
  • csaf_redhat · RHBA-2025:1597Red Hat Bug Fix Advisory: Red Hat Quay v3.9.10 bug fix release
  • csaf_redhat · RHSA-2021:0851Red Hat Security Advisory: pki-core security and bug fix update
  • csaf_redhat · RHSA-2025:1329Red Hat Security Advisory: doxygen security update
  • csaf_redhat · RHSA-2025:1216Red Hat Security Advisory: tbb security update
  • csaf_redhat · RHSA-2025:1255Red Hat Security Advisory: doxygen security update
  • csaf_redhat · RHSA-2023:0552Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.9 Security update
  • csaf_redhat · RHSA-2023:0554Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.9 Security update
  • csaf_redhat · RHSA-2023:1049Red Hat Security Advisory: Red Hat Single Sign-On 7.6.2 security update
  • csaf_redhat · RHSA-2025:1309Red Hat Security Advisory: gcc-toolset-13-gcc security update
  • csaf_redhat · RHSA-2025:1346Red Hat Security Advisory: gcc security update
  • csaf_ncscnl · NCSC-2024-0417Kwetsbaarheden verholpen in Oracle Fusion Middleware
  • csaf_redhat · RHSA-2021:0778Red Hat Security Advisory: Red Hat Ansible Tower 3.6.7-1 - Container security and bug fix update
  • csaf_redhat · RHSA-2025:1301Red Hat Security Advisory: gcc security update
  • csaf_redhat · RHSA-2025:1311Red Hat Security Advisory: gcc security update
  • csaf_redhat · RHSA-2025:1211Red Hat Security Advisory: tbb security update
  • csaf_redhat · RHSA-2025:1308Red Hat Security Advisory: gcc security update
  • csaf_redhat · RHSA-2022:6393Red Hat Security Advisory: RHV Manager (ovirt-engine) [ovirt-4.5.2] bug fix and security update
  • csaf_redhat · RHSA-2023:0556Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.9 Security update
  • csaf_redhat · RHSA-2025:1310Red Hat Security Advisory: gcc security update
  • csaf_redhat · RHSA-2025:1304Red Hat Security Advisory: gcc security update
  • csaf_redhat · RHSA-2020:4298Red Hat Security Advisory: OpenShift Container Platform 4.6.1 image security update
  • csaf_redhat · RHSA-2021:0860Red Hat Security Advisory: ipa security and bug fix update
  • csaf_redhat · RHSA-2025:2426Red Hat Security Advisory: pki-core security update
  • csaf_redhat · RHSA-2025:1314Red Hat Security Advisory: doxygen security update
  • csaf_redhat · RHSA-2020:4847Red Hat Security Advisory: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update
  • csaf_redhat · RHSA-2023:1043Red Hat Security Advisory: Red Hat Single Sign-On 7.6.2 security update on RHEL 7
Recommended actionPatch only the product branches with a verified fix

CISA confirms exploitation in the wild and lists 2025-02-13 as the remediation due date. Verified remediation exists for at least one product or source, but 4 structured product or package states remain unresolved. Apply remediation only to the exact product branch confirmed by its source.

Fix availability varies by product
01

What, why and how

JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in the context of the user's browser.

What

JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in the context of the user's browser.

Why

Attacker-controlled content can reach a browser as executable script without sufficient output encoding or sanitisation.

How

An attacker operating through a network path may attempt exploitation without authentication after a user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

What

JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in the context of the user's browser.

Why

Attacker-controlled content can reach a browser as executable script without sufficient output encoding or sanitisation.

How

An attacker operating through a network path may attempt exploitation without authentication after a user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
Confirmed in the wild

CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-23.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
Reference recorded

A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.

Likely attack path
a network path → Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') → cause the confidentiality, integrity or availability impact described by the vendor
Attack surface
Network
Privileges required
None: unauthenticated exploitation is possible
User interaction
Required interaction required
Attack complexity
High: exploitation depends on specific conditions
Security boundary
Changed: exploitation can affect a different security authority
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-79 ↗

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVNetworkAttack vector: The vulnerable component can be reached over a network.ACHighAttack complexity: Successful exploitation depends on specific conditions outside the attacker's direct control.PRNonePrivileges required: The attacker does not need an account or existing privileges.UIRequiredUser interaction: Another user must perform an action for exploitation to succeed.SChangedScope: The attack can affect a component governed by a different security authority.CHighConfidentiality impact: A successful attack can cause a major loss.ILowIntegrity impact: A successful attack can cause a limited loss.ANoneAvailability impact: No direct loss is represented by this metric.
Post-exploitation / living off the land
No specific living-off-the-land technique is confirmed in the structured sources. Monitor normal administration tools for activity inconsistent with the affected service's baseline.
NetworkUnauthenticatedCWE-79CISA KEVPublic exploit reference
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

ENISA EUVD · EUVD-2020-0387Known-exploited evidence recorded

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

Official EUVD record ↗
BSI · German · WID-SEC-2025-1459Dell Data Protection Advisor: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, und um weitere nicht näher spezifizierte Angriffe durchzuführen.

Official advisory ↗
BSI · German · WID-SEC-2024-3191Oracle Fusion Middleware: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2023-0239Red Hat JBoss Enterprise Application Platform: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat JBoss Enterprise Application Platform ausnutzen, um beliebigen Programmcode auszuführen, ein Cross-Site-Scritping-Angriff durchzuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen oder Sicherheitsvorkehrungen zu umgehen.

Official advisory ↗
BSI · German · WID-SEC-2023-0063Juniper Junos Space: Mehrere Schwachstellen

Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Juniper Junos Space ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen, beliebigen Code auszuführen und seine Privilegien zu erweitern.

Official advisory ↗
BSI · German · WID-SEC-2024-1872IBM QRadar SIEM: Mehrere Schwachstellen

Ein entfernter anonymer oder authentifizierter Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, Dateien zu manipulieren, einen Denial-of-Service-Zustand auszulösen und einen Cross-Site-Scripting-Angriff durchzuführen.

Official advisory ↗
BSI · German · WID-SEC-2022-1347jQuery: Mehrere Schwachstellen ermöglichen Cross-Site Scripting

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in jQuery ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.

Official advisory ↗
Cyber Security Agency of Singapore · English · CSA-SB-20200506Security Bulletin 06 May 2020

The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 06 May 2020, published on 6 May 2020. Open the linked bulletin for the product, severity and reference information published in that issue.

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-1165Multiples vulnérabilités dans les produits IBM

ord?id=CVE-2019-10099 Référence CVE CVE-2019-11358 https://www.cve.org/CVERecord?id=CVE-2019-11358 Référence CVE CVE-2019-14893 https://www.cve.org/CVERecord?id=CVE-2019-14893 Référence CVE CVE-2019-16869 https://www.cve.org/CVERecord?id=CVE-2019-16869 Référence CVE CVE-2019-20444 https://www.cve.org/CVERecord?id=CVE-2019-20444 Référence CVE CVE-2019-20445 https://www.cve.org/CVERecord?id=CVE-2019-20445 Référence CVE CVE-2019-8331 https://www.cve.org/CVERecord?id=CVE-2019-8331 Référence CVE CVE-2020-10683 https://www.cve.org/CVERecord?id=CVE-2020-10683 Référence CVE CVE-2020-11022 https://www.cve.org/CVERecord?id=CVE-2020-11022 Référence CVE CVE-2020-11023 https://www.cve.org/CVERecord?id=CVE-2020-11023 Référence CVE CVE-2020-11988 https://www.cve.org/CVERecord?id=CVE-2020-11988 Référence CVE CVE-2020-13955 https://www.cve.org/CVERecord?id=CVE-2020-13955 Référence CVE CVE-2020-26555 https://www.cve.org/CVERecord?id=CVE-2020-26555 Référence CVE CVE-2020-26945 https://www.cve.org/CVERecord?id=CVE-2020-26945 Référence CVE CVE-2020-7656 https://www.cve.org/CVERecord?id=CVE-2020-7656 Référence CVE CVE-2020-9480 https://www.cve.org/CVERecord?id=CVE-2020-9480 Référence CVE CVE-2020-9492 https://www.cve.org/CVERecord?id=CVE-2020-9492 Référence CVE CVE-2021-21290 https://www.cve.org/CVERecord?id=CVE-20

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0218Multiples vulnérabilités dans les produits VMware

ERecord?id=CVE-2018-25032 Référence CVE CVE-2018-9996 https://www.cve.org/CVERecord?id=CVE-2018-9996 Référence CVE CVE-2019-13232 https://www.cve.org/CVERecord?id=CVE-2019-13232 Référence CVE CVE-2019-25013 https://www.cve.org/CVERecord?id=CVE-2019-25013 Référence CVE CVE-2019-2708 https://www.cve.org/CVERecord?id=CVE-2019-2708 Référence CVE CVE-2019-9076 https://www.cve.org/CVERecord?id=CVE-2019-9076 Référence CVE CVE-2020-10029 https://www.cve.org/CVERecord?id=CVE-2020-10029 Référence CVE CVE-2020-10543 https://www.cve.org/CVERecord?id=CVE-2020-10543 Référence CVE CVE-2020-10878 https://www.cve.org/CVERecord?id=CVE-2020-10878 Référence CVE CVE-2020-11023 https://www.cve.org/CVERecord?id=CVE-2020-11023 Référence CVE CVE-2020-12723 https://www.cve.org/CVERecord?id=CVE-2020-12723 Référence CVE CVE-2020-12762 https://www.cve.org/CVERecord?id=CVE-2020-12762 Référence CVE CVE-2020-16599 https://www.cve.org/CVERecord?id=CVE-2020-16599 Référence CVE CVE-2020-1752 https://www.cve.org/CVERecord?id=CVE-2020-1752 Référence CVE CVE-2020-19726 https://www.cve.org/CVERecord?id=CVE-2020-19726 Référence CVE CVE-2020-22916 https://www.cve.org/CVERecord?id=CVE-2020-22916 Référence CVE CVE-2020-27618 https://www.cve.org/CVERecord?id=CVE-2020-27618 Référence CVE CVE-2020-29562 https://www.cve.org/CVERecord?id=CV

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0855Multiples vulnérabilités dans les produits Juniper Networks

rg/CVERecord?id=CVE-2015-3253 Référence CVE CVE-2015-5377 https://www.cve.org/CVERecord?id=CVE-2015-5377 Référence CVE CVE-2018-17244 https://www.cve.org/CVERecord?id=CVE-2018-17244 Référence CVE CVE-2018-17247 https://www.cve.org/CVERecord?id=CVE-2018-17247 Référence CVE CVE-2018-3823 https://www.cve.org/CVERecord?id=CVE-2018-3823 Référence CVE CVE-2018-3824 https://www.cve.org/CVERecord?id=CVE-2018-3824 Référence CVE CVE-2018-3826 https://www.cve.org/CVERecord?id=CVE-2018-3826 Référence CVE CVE-2018-3831 https://www.cve.org/CVERecord?id=CVE-2018-3831 Référence CVE CVE-2019-12900 https://www.cve.org/CVERecord?id=CVE-2019-12900 Référence CVE CVE-2020-11023 https://www.cve.org/CVERecord?id=CVE-2020-11023 Référence CVE CVE-2021-22146 https://www.cve.org/CVERecord?id=CVE-2021-22146 Référence CVE CVE-2021-3903 https://www.cve.org/CVERecord?id=CVE-2021-3903 Référence CVE CVE-2021-40153 https://www.cve.org/CVERecord?id=CVE-2021-40153 Référence CVE CVE-2021-4104 https://www.cve.org/CVERecord?id=CVE-2021-4104 Référence CVE CVE-2021-41043 https://www.cve.org/CVERecord?id=CVE-2021-41043 Référence CVE CVE-2021-41072 https://www.cve.org/CVERecord?id=CVE-2021-41072 Référence CVE CVE-2021-42550 https://www.cve.org/CVERecord?id=CVE-2021-42550 Référence CVE CVE-2021-44228 https://www.cve.org/CVERecord?id=CVE-

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0693Multiples vulnérabilités dans VMware Tanzu

pport-content-notification/-/external/content/SecurityAdvisories/0/36035 Bulletin de sécurité VMware 36036 du 14 août 2025 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36036 Bulletin de sécurité VMware 36037 du 14 août 2025 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36037 Bulletin de sécurité VMware 36038 du 14 août 2025 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36038 Référence CVE CVE-2019-12900 https://www.cve.org/CVERecord?id=CVE-2019-12900 Référence CVE CVE-2020-11023 https://www.cve.org/CVERecord?id=CVE-2020-11023 Référence CVE CVE-2021-20197 https://www.cve.org/CVERecord?id=CVE-2021-20197 Référence CVE CVE-2021-32256 https://www.cve.org/CVERecord?id=CVE-2021-32256 Référence CVE CVE-2021-3572 https://www.cve.org/CVERecord?id=CVE-2021-3572 Référence CVE CVE-2021-3826 https://www.cve.org/CVERecord?id=CVE-2021-3826 Référence CVE CVE-2021-3927 https://www.cve.org/CVERecord?id=CVE-2021-3927 Référence CVE CVE-2021-3928 https://www.cve.org/CVERecord?id=CVE-2021-3928 Référence CVE CVE-2021-3968 https://www.cve.org/CVERecord?id=CVE-2021-3968 Référence CVE CVE-2021-3973 https://www.cve.org/CVERecord?id=CVE-2021-39

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0524Multiples vulnérabilités dans VMware Tanzu

/CVERecord?id=CVE-2019-8396 Référence CVE CVE-2019-8397 https://www.cve.org/CVERecord?id=CVE-2019-8397 Référence CVE CVE-2019-8398 https://www.cve.org/CVERecord?id=CVE-2019-8398 Référence CVE CVE-2019-9151 https://www.cve.org/CVERecord?id=CVE-2019-9151 Référence CVE CVE-2019-9152 https://www.cve.org/CVERecord?id=CVE-2019-9152 Référence CVE CVE-2020-10809 https://www.cve.org/CVERecord?id=CVE-2020-10809 Référence CVE CVE-2020-10810 https://www.cve.org/CVERecord?id=CVE-2020-10810 Référence CVE CVE-2020-10811 https://www.cve.org/CVERecord?id=CVE-2020-10811 Référence CVE CVE-2020-10812 https://www.cve.org/CVERecord?id=CVE-2020-10812 Référence CVE CVE-2020-11023 https://www.cve.org/CVERecord?id=CVE-2020-11023 Référence CVE CVE-2020-18232 https://www.cve.org/CVERecord?id=CVE-2020-18232 Référence CVE CVE-2020-18494 https://www.cve.org/CVERecord?id=CVE-2020-18494 Référence CVE CVE-2021-26220 https://www.cve.org/CVERecord?id=CVE-2021-26220 Référence CVE CVE-2021-26221 https://www.cve.org/CVERecord?id=CVE-2021-26221 Référence CVE CVE-2021-26222 https://www.cve.org/CVERecord?id=CVE-2021-26222 Référence CVE CVE-2021-30485 https://www.cve.org/CVERecord?id=CVE-2021-30485 Référence CVE CVE-2021-31229 https://www.cve.org/CVERecord?id=CVE-2021-31229 Référence CVE CVE-2021-31347 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0422Multiples vulnérabilités dans IBM QRadar SIEM

à 7.5.0 UP12 QRadar SIEM versions 7.5.x antérieures à 7.5.0 UP12 Résumé De multiples vulnérabilités ont été découvertes dans IBM QRadar SIEM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données. Solutions Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation). Documentation Bulletin de sécurité IBM 7233394 du 14 mai 2025 https://www.ibm.com/support/pages/node/7233394 Référence CVE CVE-2019-12900 https://www.cve.org/CVERecord?id=CVE-2019-12900 Référence CVE CVE-2020-11023 https://www.cve.org/CVERecord?id=CVE-2020-11023 Référence CVE CVE-2020-13955 https://www.cve.org/CVERecord?id=CVE-2020-13955 Référence CVE CVE-2022-34169 https://www.cve.org/CVERecord?id=CVE-2022-34169 Référence CVE CVE-2022-39135 https://www.cve.org/CVERecord?id=CVE-2022-39135 Référence CVE CVE-2022-41678 https://www.cve.org/CVERecord?id=CVE-2022-41678 Référence CVE CVE-2022-42003 https://www.cve.org/CVERecord?id=CVE-2022-42003 Référence CVE CVE-2022-42004 https://www.cve.org/CVERecord?id=CVE-2022-42004 Référence CVE CVE-2022-49043 https://www.cve.org/CVERecord?id=CVE-2022-49043 Référence CVE CVE-2023-0286 https://www.cve.org/CVERecord?id=C

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0401Multiples vulnérabilités dans Juniper Networks Secure Analytics

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation). Documentation Bulletin de sécurité Juniper Networks JSA98556 du 13 mai 2025 https://supportportal.juniper.net/s/article/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP11-IF03 Référence CVE CVE-2016-2193 https://www.cve.org/CVERecord?id=CVE-2016-2193 Référence CVE CVE-2017-9047 https://www.cve.org/CVERecord?id=CVE-2017-9047 Référence CVE CVE-2018-12699 https://www.cve.org/CVERecord?id=CVE-2018-12699 Référence CVE CVE-2019-12900 https://www.cve.org/CVERecord?id=CVE-2019-12900 Référence CVE CVE-2020-11023 https://www.cve.org/CVERecord?id=CVE-2020-11023 Référence CVE CVE-2020-21469 https://www.cve.org/CVERecord?id=CVE-2020-21469 Référence CVE CVE-2021-37533 https://www.cve.org/CVERecord?id=CVE-2021-37533 Référence CVE CVE-2022-48773 https://www.cve.org/CVERecord?id=CVE-2022-48773 Référence CVE CVE-2022-49043 https://www.cve.org/CVERecord?id=CVE-2022-49043 Référence CVE CVE-2023-2454 https://www.cve.org/CVERecord?id=CVE-2023-2454 Référence CVE CVE-2023-2455 https://www.cve.org/CVERecord?id=CVE-2023-2455 Référence CVE CVE-2023-37920 https://www.cve.org/CVERecord?id=CVE-2023-37920 Référence CVE CVE-2023-52492 https://www.cve.org/CVERecord?id=CVE-

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0370Multiples vulnérabilités dans les produits IBM

.cve.org/CVERecord?id=CVE-2016-0714 Référence CVE CVE-2016-5018 https://www.cve.org/CVERecord?id=CVE-2016-5018 Référence CVE CVE-2016-5388 https://www.cve.org/CVERecord?id=CVE-2016-5388 Référence CVE CVE-2016-6796 https://www.cve.org/CVERecord?id=CVE-2016-6796 Référence CVE CVE-2016-6797 https://www.cve.org/CVERecord?id=CVE-2016-6797 Référence CVE CVE-2016-6816 https://www.cve.org/CVERecord?id=CVE-2016-6816 Référence CVE CVE-2016-8735 https://www.cve.org/CVERecord?id=CVE-2016-8735 Référence CVE CVE-2017-5647 https://www.cve.org/CVERecord?id=CVE-2017-5647 Référence CVE CVE-2017-9047 https://www.cve.org/CVERecord?id=CVE-2017-9047 Référence CVE CVE-2020-11023 https://www.cve.org/CVERecord?id=CVE-2020-11023 Référence CVE CVE-2020-8022 https://www.cve.org/CVERecord?id=CVE-2020-8022 Référence CVE CVE-2022-49043 https://www.cve.org/CVERecord?id=CVE-2022-49043 Référence CVE CVE-2023-52922 https://www.cve.org/CVERecord?id=CVE-2023-52922 Référence CVE CVE-2024-11218 https://www.cve.org/CVERecord?id=CVE-2024-11218 Référence CVE CVE-2024-40695 https://www.cve.org/CVERecord?id=CVE-2024-40695 Référence CVE CVE-2024-50302 https://www.cve.org/CVERecord?id=CVE-2024-50302 Référence CVE CVE-2024-51466 https://www.cve.org/CVERecord?id=CVE-2024-51466 Référence CVE CVE-2024-53197 https://www.cve.org/CVERecord?id=CV

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0214Multiples vulnérabilités dans les produits IBM

eur pour l'obtention des correctifs (cf. section Documentation). Documentation Bulletin de sécurité IBM 7185257 du 10 mars 2025 https://www.ibm.com/support/pages/node/7185257 Bulletin de sécurité IBM 7185353 du 11 mars 2025 https://www.ibm.com/support/pages/node/7185353 Bulletin de sécurité IBM 7185675 du 13 mars 2025 https://www.ibm.com/support/pages/node/7185675 Bulletin de sécurité IBM 7185937 du 14 mars 2025 https://www.ibm.com/support/pages/node/7185937 Bulletin de sécurité IBM 7185938 du 14 mars 2025 https://www.ibm.com/support/pages/node/7185938 Référence CVE CVE-2019-12900 https://www.cve.org/CVERecord?id=CVE-2019-12900 Référence CVE CVE-2020-11023 https://www.cve.org/CVERecord?id=CVE-2020-11023 Référence CVE CVE-2021-32803 https://www.cve.org/CVERecord?id=CVE-2021-32803 Référence CVE CVE-2021-32804 https://www.cve.org/CVERecord?id=CVE-2021-32804 Référence CVE CVE-2022-1365 https://www.cve.org/CVERecord?id=CVE-2022-1365 Référence CVE CVE-2022-1471 https://www.cve.org/CVERecord?id=CVE-2022-1471 Référence CVE CVE-2022-24302 https://www.cve.org/CVERecord?id=CVE-2022-24302 Référence CVE CVE-2022-25857 https://www.cve.org/CVERecord?id=CVE-2022-25857 Référence CVE CVE-2022-35737 https://www.cve.org/CVERecord?id=CVE-2022-35737 Référence CVE CVE-2022-38900 https://www.cve.org/CVERecord?id=CVE-

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-1103Multiples vulnérabilités dans les produits IBM

ERecord?id=CVE-2019-14973 Référence CVE CVE-2019-17006 https://www.cve.org/CVERecord?id=CVE-2019-17006 Référence CVE CVE-2019-17007 https://www.cve.org/CVERecord?id=CVE-2019-17007 Référence CVE CVE-2019-17023 https://www.cve.org/CVERecord?id=CVE-2019-17023 Référence CVE CVE-2019-17546 https://www.cve.org/CVERecord?id=CVE-2019-17546 Référence CVE CVE-2019-6128 https://www.cve.org/CVERecord?id=CVE-2019-6128 Référence CVE CVE-2019-7317 https://www.cve.org/CVERecord?id=CVE-2019-7317 Référence CVE CVE-2019-8331 https://www.cve.org/CVERecord?id=CVE-2019-8331 Référence CVE CVE-2020-11022 https://www.cve.org/CVERecord?id=CVE-2020-11022 Référence CVE CVE-2020-11023 https://www.cve.org/CVERecord?id=CVE-2020-11023 Référence CVE CVE-2020-12400 https://www.cve.org/CVERecord?id=CVE-2020-12400 Référence CVE CVE-2020-12401 https://www.cve.org/CVERecord?id=CVE-2020-12401 Référence CVE CVE-2020-12403 https://www.cve.org/CVERecord?id=CVE-2020-12403 Référence CVE CVE-2020-15110 https://www.cve.org/CVERecord?id=CVE-2020-15110 Référence CVE CVE-2020-18768 https://www.cve.org/CVERecord?id=CVE-2020-18768 Référence CVE CVE-2020-19131 https://www.cve.org/CVERecord?id=CVE-2020-19131 Référence CVE CVE-2020-19144 https://www.cve.org/CVERecord?id=CVE-2020-19144 Référence CVE CVE-2020-19189 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0741Multiples vulnérabilités dans Juniper Secure Analytics

SA86686 du 30 septembre 2024 https://supportportal.juniper.net/s/article/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP9-IF02 Référence CVE CVE-2018-20060 https://www.cve.org/CVERecord?id=CVE-2018-20060 Référence CVE CVE-2018-25091 https://www.cve.org/CVERecord?id=CVE-2018-25091 Référence CVE CVE-2019-11358 https://www.cve.org/CVERecord?id=CVE-2019-11358 Référence CVE CVE-2019-14865 https://www.cve.org/CVERecord?id=CVE-2019-14865 Référence CVE CVE-2019-25162 https://www.cve.org/CVERecord?id=CVE-2019-25162 Référence CVE CVE-2020-11022 https://www.cve.org/CVERecord?id=CVE-2020-11022 Référence CVE CVE-2020-11023 https://www.cve.org/CVERecord?id=CVE-2020-11023 Référence CVE CVE-2020-13936 https://www.cve.org/CVERecord?id=CVE-2020-13936 Référence CVE CVE-2020-15778 https://www.cve.org/CVERecord?id=CVE-2020-15778 Référence CVE CVE-2020-23064 https://www.cve.org/CVERecord?id=CVE-2020-23064 Référence CVE CVE-2020-26555 https://www.cve.org/CVERecord?id=CVE-2020-26555 Référence CVE CVE-2020-36777 https://www.cve.org/CVERecord?id=CVE-2020-36777 Référence CVE CVE-2021-33198 https://www.cve.org/CVERecord?id=CVE-2021-33198 Référence CVE CVE-2021-34558 https://www.cve.org/CVERecord?id=CVE-2021-34558 Référence CVE CVE-2021-40153 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0737Multiples vulnérabilités dans Moxa OnCell 3120-LTE-1 Series

De multiples vulnérabilités ont été découvertes dans Moxa OnCell 3120-LTE-1 Series. Elles permettent à un attaquant de provoquer une injection de code indirecte à distance (XSS).

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0579Multiples vulnérabilités dans les produits IBM

écurité IBM 7159934 du 10 juillet 2024 https://www.ibm.com/support/pages/node/7159934 Bulletin de sécurité IBM 7160013 du 11 juillet 2024 https://www.ibm.com/support/pages/node/7160013 Bulletin de sécurité IBM 7160014 du 11 juillet 2024 https://www.ibm.com/support/pages/node/7160014 Bulletin de sécurité IBM 7160017 du 11 juillet 2024 https://www.ibm.com/support/pages/node/7160017 Bulletin de sécurité IBM 7160134 du 12 juillet 2024 https://www.ibm.com/support/pages/node/7160134 Référence CVE CVE-2019-11358 https://www.cve.org/CVERecord?id=CVE-2019-11358 Référence CVE CVE-2020-11022 https://www.cve.org/CVERecord?id=CVE-2020-11022 Référence CVE CVE-2020-11023 https://www.cve.org/CVERecord?id=CVE-2020-11023 Référence CVE CVE-2020-13936 https://www.cve.org/CVERecord?id=CVE-2020-13936 Référence CVE CVE-2020-15778 https://www.cve.org/CVERecord?id=CVE-2020-15778 Référence CVE CVE-2020-23064 https://www.cve.org/CVERecord?id=CVE-2020-23064 Référence CVE CVE-2021-40153 https://www.cve.org/CVERecord?id=CVE-2021-40153 Référence CVE CVE-2021-41072 https://www.cve.org/CVERecord?id=CVE-2021-41072 Référence CVE CVE-2022-3287 https://www.cve.org/CVERecord?id=CVE-2022-3287 Référence CVE CVE-2023-25193 https://www.cve.org/CVERecord?id=CVE-2023-25193 Référence CVE CVE-2023-29483 https://www.cve.org/CVERecord?id=CV

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0508Multiples vulnérabilités dans les produits Moxa

De multiples vulnérabilités ont été découvertes dans les produits Moxa. Elles permettent à un attaquant de provoquer une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0459Multiples vulnérabilités dans les produits IBM

d?id=CVE-2019-19203 Référence CVE CVE-2019-19204 https://www.cve.org/CVERecord?id=CVE-2019-19204 Référence CVE CVE-2019-20330 https://www.cve.org/CVERecord?id=CVE-2019-20330 Référence CVE CVE-2020-10650 https://www.cve.org/CVERecord?id=CVE-2020-10650 Référence CVE CVE-2020-10672 https://www.cve.org/CVERecord?id=CVE-2020-10672 Référence CVE CVE-2020-10673 https://www.cve.org/CVERecord?id=CVE-2020-10673 Référence CVE CVE-2020-10968 https://www.cve.org/CVERecord?id=CVE-2020-10968 Référence CVE CVE-2020-10969 https://www.cve.org/CVERecord?id=CVE-2020-10969 Référence CVE CVE-2020-11022 https://www.cve.org/CVERecord?id=CVE-2020-11022 Référence CVE CVE-2020-11023 https://www.cve.org/CVERecord?id=CVE-2020-11023 Référence CVE CVE-2020-11111 https://www.cve.org/CVERecord?id=CVE-2020-11111 Référence CVE CVE-2020-11112 https://www.cve.org/CVERecord?id=CVE-2020-11112 Référence CVE CVE-2020-11113 https://www.cve.org/CVERecord?id=CVE-2020-11113 Référence CVE CVE-2020-11619 https://www.cve.org/CVERecord?id=CVE-2020-11619 Référence CVE CVE-2020-11620 https://www.cve.org/CVERecord?id=CVE-2020-11620 Référence CVE CVE-2020-13956 https://www.cve.org/CVERecord?id=CVE-2020-13956 Référence CVE CVE-2020-14060 https://www.cve.org/CVERecord?id=CVE-2020-14060 Référence CVE CVE-2020-14061 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0907Multiples vulnérabilités dans Moxa PT-G503

De multiples vulnérabilités ont été découvertes dans Moxa PT-G503. Certaines d'entre elles permettent à un attaquant de provoquer un contournement de la politique de sécurité, une atteinte à l'intégrité des données et une atteinte à la confidentialité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0357Multiples vulnérabilités dans IBM Cognos

Record?id=CVE-2017-7656 Référence CVE CVE-2017-7657 https://www.cve.org/CVERecord?id=CVE-2017-7657 Référence CVE CVE-2017-7658 https://www.cve.org/CVERecord?id=CVE-2017-7658 Référence CVE CVE-2018-12536 https://www.cve.org/CVERecord?id=CVE-2018-12536 Référence CVE CVE-2018-12545 https://www.cve.org/CVERecord?id=CVE-2018-12545 Référence CVE CVE-2019-10241 https://www.cve.org/CVERecord?id=CVE-2019-10241 Référence CVE CVE-2019-10247 https://www.cve.org/CVERecord?id=CVE-2019-10247 Référence CVE CVE-2019-11358 https://www.cve.org/CVERecord?id=CVE-2019-11358 Référence CVE CVE-2020-11022 https://www.cve.org/CVERecord?id=CVE-2020-11022 Référence CVE CVE-2020-11023 https://www.cve.org/CVERecord?id=CVE-2020-11023 Référence CVE CVE-2020-27218 https://www.cve.org/CVERecord?id=CVE-2020-27218 Référence CVE CVE-2020-27223 https://www.cve.org/CVERecord?id=CVE-2020-27223 Référence CVE CVE-2021-28165 https://www.cve.org/CVERecord?id=CVE-2021-28165 Référence CVE CVE-2021-28169 https://www.cve.org/CVERecord?id=CVE-2021-28169 Référence CVE CVE-2021-29425 https://www.cve.org/CVERecord?id=CVE-2021-29425 Référence CVE CVE-2021-34428 https://www.cve.org/CVERecord?id=CVE-2021-34428 Référence CVE CVE-2021-37533 https://www.cve.org/CVERecord?id=CVE-2021-37533 Référence CVE CVE-2022-2047 https://www.cve.org/CVERecord?id=C

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0250Multiples vulnérabilités dans les produits IBM

De multiples vulnérabilités ont été corrigées dans les produits IBM . Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité, une injection de code indirecte à distance (XSS), une élévation de privilèges et une atteinte à la confidentialité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0219Multiples vulnérabilités dans IBM Sterling B2B Integrator

De multiples vulnérabilités ont été découvertes dans IBM Sterling B2B Integrator. Certaines d'entre elles permettent à un attaquant de provoquer un contournement de la politique de sécurité, une atteinte à l'intégrité des données et une atteinte à la confidentialité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0208Multiples vulnérabilités dans Nessus

De multiples vulnérabilités ont été découvertes dans les produits Tenable . Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0190Multiples vulnérabilités dans Tenable Nessus

De multiples vulnérabilités ont été découvertes dans Tenable Nessus. Certaines d'entre elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, une exécution de code arbitraire à distance et un déni de service à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-928Multiples vulnérabilités dans les produits IBM

ERecord?id=CVE-2019-10202 Référence CVE CVE-2019-10744 https://www.cve.org/CVERecord?id=CVE-2019-10744 Référence CVE CVE-2019-11358 https://www.cve.org/CVERecord?id=CVE-2019-11358 Référence CVE CVE-2019-16935 https://www.cve.org/CVERecord?id=CVE-2019-16935 Référence CVE CVE-2019-18348 https://www.cve.org/CVERecord?id=CVE-2019-18348 Référence CVE CVE-2019-9636 https://www.cve.org/CVERecord?id=CVE-2019-9636 Référence CVE CVE-2019-9740 https://www.cve.org/CVERecord?id=CVE-2019-9740 Référence CVE CVE-2019-9947 https://www.cve.org/CVERecord?id=CVE-2019-9947 Référence CVE CVE-2020-11022 https://www.cve.org/CVERecord?id=CVE-2020-11022 Référence CVE CVE-2020-11023 https://www.cve.org/CVERecord?id=CVE-2020-11023 Référence CVE CVE-2020-13936 https://www.cve.org/CVERecord?id=CVE-2020-13936 Référence CVE CVE-2020-15523 https://www.cve.org/CVERecord?id=CVE-2020-15523 Référence CVE CVE-2020-26116 https://www.cve.org/CVERecord?id=CVE-2020-26116 Référence CVE CVE-2020-27619 https://www.cve.org/CVERecord?id=CVE-2020-27619 Référence CVE CVE-2020-28469 https://www.cve.org/CVERecord?id=CVE-2020-28469 Référence CVE CVE-2020-4051 https://www.cve.org/CVERecord?id=CVE-2020-4051 Référence CVE CVE-2020-7598 https://www.cve.org/CVERecord?id=CVE-2020-7598 Référence CVE CVE-2020-7656 https://www.cve.org/CVERecord?id=CVE-2

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-924Multiples vulnérabilités dans IBM QRadar

etin de sécurité IBM 6830017 du 17 octobre 2022 https://www.ibm.com/support/pages/node/6830017 Référence CVE CVE-2018-16487 https://www.cve.org/CVERecord?id=CVE-2018-16487 Référence CVE CVE-2018-25031 https://www.cve.org/CVERecord?id=CVE-2018-25031 Référence CVE CVE-2018-3721 https://www.cve.org/CVERecord?id=CVE-2018-3721 Référence CVE CVE-2019-1010266 https://www.cve.org/CVERecord?id=CVE-2019-1010266 Référence CVE CVE-2019-10744 https://www.cve.org/CVERecord?id=CVE-2019-10744 Référence CVE CVE-2019-11358 https://www.cve.org/CVERecord?id=CVE-2019-11358 Référence CVE CVE-2020-11022 https://www.cve.org/CVERecord?id=CVE-2020-11022 Référence CVE CVE-2020-11023 https://www.cve.org/CVERecord?id=CVE-2020-11023 Référence CVE CVE-2020-28469 https://www.cve.org/CVERecord?id=CVE-2020-28469 Référence CVE CVE-2020-7598 https://www.cve.org/CVERecord?id=CVE-2020-7598 Référence CVE CVE-2020-7788 https://www.cve.org/CVERecord?id=CVE-2020-7788 Référence CVE CVE-2020-8203 https://www.cve.org/CVERecord?id=CVE-2020-8203 Référence CVE CVE-2021-22959 https://www.cve.org/CVERecord?id=CVE-2021-22959 Référence CVE CVE-2021-22960 https://www.cve.org/CVERecord?id=CVE-2021-22960 Référence CVE CVE-2021-23337 https://www.cve.org/CVERecord?id=CVE-2021-23337 Référence CVE CVE-2021-23346 https://www.cve.org/CVERecord?id=CVE-20

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-266Multiples vulnérabilités dans IBM WebSphere Service Registry and Repository

De multiples vulnérabilités ont été découvertes dans IBM WebSphere Service Registry and Repository. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-056Multiples vulnérabilités dans Oracle WebLogic Server

découvertes dans Oracle WebLogic Server. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à l'intégrité des données. Solution Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation). Documentation Bulletin de sécurité Oracle cpujan2022.html du 18 janvier 2022 https://www.oracle.com/security-alerts/cpujan2022.html#AppendixFMW Référence CVE CVE-2018-1324 https://www.cve.org/CVERecord?id=CVE-2018-1324 Référence CVE CVE-2019-10219 https://www.cve.org/CVERecord?id=CVE-2019-10219 Référence CVE CVE-2020-11023 https://www.cve.org/CVERecord?id=CVE-2020-11023 Référence CVE CVE-2020-13956 https://www.cve.org/CVERecord?id=CVE-2020-13956 Référence CVE CVE-2020-2934 https://www.cve.org/CVERecord?id=CVE-2020-2934 Référence CVE CVE-2020-5258 https://www.cve.org/CVERecord?id=CVE-2020-5258 Référence CVE CVE-2021-27568 https://www.cve.org/CVERecord?id=CVE-2021-27568 Référence CVE CVE-2021-29425 https://www.cve.org/CVERecord?id=CVE-2021-29425 Référence CVE CVE-2021-4104 https://www.cve.org/CVERecord?id=CVE-2021-4104 Référence CVE CVE-2021-44832 https://www.cve.org/CVERecord?id=CVE-2021-44832 Référence CVE CVE-2022-21252 https://www.cve.org/CVERecord?id=CVE-20

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-943Multiples vulnérabilités dans les produits IBM

d?id=CVE-2019-10172 Référence CVE CVE-2019-14892 https://www.cve.org/CVERecord?id=CVE-2019-14892 Référence CVE CVE-2019-14893 https://www.cve.org/CVERecord?id=CVE-2019-14893 Référence CVE CVE-2020-10672 https://www.cve.org/CVERecord?id=CVE-2020-10672 Référence CVE CVE-2020-10673 https://www.cve.org/CVERecord?id=CVE-2020-10673 Référence CVE CVE-2020-10683 https://www.cve.org/CVERecord?id=CVE-2020-10683 Référence CVE CVE-2020-10968 https://www.cve.org/CVERecord?id=CVE-2020-10968 Référence CVE CVE-2020-10969 https://www.cve.org/CVERecord?id=CVE-2020-10969 Référence CVE CVE-2020-11022 https://www.cve.org/CVERecord?id=CVE-2020-11022 Référence CVE CVE-2020-11023 https://www.cve.org/CVERecord?id=CVE-2020-11023 Référence CVE CVE-2020-11111 https://www.cve.org/CVERecord?id=CVE-2020-11111 Référence CVE CVE-2020-11112 https://www.cve.org/CVERecord?id=CVE-2020-11112 Référence CVE CVE-2020-11113 https://www.cve.org/CVERecord?id=CVE-2020-11113 Référence CVE CVE-2020-11619 https://www.cve.org/CVERecord?id=CVE-2020-11619 Référence CVE CVE-2020-11620 https://www.cve.org/CVERecord?id=CVE-2020-11620 Référence CVE CVE-2020-13956 https://www.cve.org/CVERecord?id=CVE-2020-13956 Référence CVE CVE-2020-14060 https://www.cve.org/CVERecord?id=CVE-2020-14060 Référence CVE CVE-2020-14061 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-770Multiples vulnérabilités dans les produits SAP

De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service, un contournement de la politique de sécurité et une atteinte à la confidentialité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-430Multiples vulnérabilités dans Tenable LCE

De multiples vulnérabilités ont été découvertes dans Tenable LCE. Elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-295Multiples vulnérabilités dans Oracle Database

De multiples vulnérabilités ont été découvertes dans Oracle Database. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à l'intégrité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-196Multiples vulnérabilités dans Moodle

De multiples vulnérabilités ont été découvertes dans Moodle. Certaines d'entre elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, un contournement de la politique de sécurité et une atteinte à la confidentialité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-130Multiples vulnérabilités dans Tenable Nessus Network Monitor

De multiples vulnérabilités ont été découvertes dans Tenable Nessus Network Monitor. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2020-AVI-775Multiples vulnérabilités dans Zimbra

De multiples vulnérabilités ont été découvertes dans Zimbra. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2020-AVI-662Multiples vulnérabilités dans Oracle Database Server

De multiples vulnérabilités ont été découvertes dans Oracle Database Server. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à l'intégrité des données. Cet avis ne liste pas les CVE pour lesquelles l'éditeur considère qu'elles ne sont pas exploitables dans le contexte d'exécution du produit.

Official advisory ↗
CERT-FR · French · CERTFR-2020-AVI-549Multiples vulnérabilités dans les produits SAP

SAPUI5_JAVA) version 7.50 Résumé De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, une exécution de code arbitraire à distance et un contournement de la politique de sécurité. Solution Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation). Documentation Bulletin de sécurité SAP du 08 septembre 2020 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700 Référence CVE CVE-2020-11022 https://www.cve.org/CVERecord?id=CVE-2020-11022 Référence CVE CVE-2020-11023 https://www.cve.org/CVERecord?id=CVE-2020-11023 Référence CVE CVE-2020-6207 https://www.cve.org/CVERecord?id=CVE-2020-6207 Référence CVE CVE-2020-6275 https://www.cve.org/CVERecord?id=CVE-2020-6275 Référence CVE CVE-2020-6282 https://www.cve.org/CVERecord?id=CVE-2020-6282 Référence CVE CVE-2020-6283 https://www.cve.org/CVERecord?id=CVE-2020-6283 Référence CVE CVE-2020-6288 https://www.cve.org/CVERecord?id=CVE-2020-6288 Référence CVE CVE-2020-6296 https://www.cve.org/CVERecord?id=CVE-2020-6296 Référence CVE CVE-2020-6302 https://www.cve.org/CVERecord?id=CVE-2020-6302 Référence CVE CVE-2020-6311 https://www.cve.org/CVERecord?id=CVE-2020-6311 R

Official advisory ↗
CERT-FR · French · CERTFR-2020-AVI-495Multiples vulnérabilités dans les produits SAP

De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, une exécution de code arbitraire à distance et un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2020-AVI-335Multiples vulnérabilités dans Joomla!

De multiples vulnérabilités ont été découvertes dans Joomla!. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité et une injection de code indirecte à distance (XSS).

Official advisory ↗
CERT-FR · French · CERTFR-2020-AVI-310Multiples vulnérabilités dans Drupal

De multiples vulnérabilités ont été découvertes dans Drupal. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité et une injection de code indirecte à distance (XSS).

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2020-005056jQuery におけるクロスサイトスクリプティングの脆弱性

jQuery には、クロスサイトスクリプティングの脆弱性が存在します。

Official advisory ↗
NCSC-NL · Dutch · NCSC-2024-0417Kwetsbaarheden verholpen in Oracle Fusion Middleware

Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: - Denial-of-Service (DoS) - Manipuleren van data - Uitvoer van willekeurige code (Administratorrechten) - Toegang tot gevoelige gegevens Omdat deze kwetsbaarheden zich bevinden in diverse Middleware producten, is niet uit te sluiten dat applicaties, draaiende op platformen ondersteund door deze middleware ook kwetsbaar zijn, danwel gevoelig voor misbruik van deze kwetsbaarheden.

Official advisory ↗
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Fix availability varies by product
Affected
Fixed
Action
Use the product-specific evidence above. Patch only products with a verified fixed release, and keep every affected or under-investigation state without a matching fix in the remediation queue.
Workaround
No verified workaround is recorded. If business-safe, reduce exposure to the affected interface and allow only trusted sources until authoritative guidance is available.
04

Evidence and provenance

Published 29 Apr 2020 · Last source change 21 Oct 2025, 23:35 UTC · CWE-79 · Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE recordCVE.org · 5.1
CVSS sourceCNA
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-08-14
European sourceENISA EUVD · EUVD-2020-0387
Product sourceVendor CSAF · Red Hat Product Security
Remediation sourceVendor CSAF · Red Hat Product Security
CWE sourceCNA
NVD statusNVD enriched

Core structured fields are present and their contributing authorities are shown above.

Material change intelligence

What changed after publication

View recent updates ↗
  1. Affected versionsThe structured affected or fixed version information changed.
    Before
    jQuery: >= 1.0.3, < 3.5.0 · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    jQuery: >= 1.0.3, < 3.5.0 · Fixed: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
    Red Hat Product Security ↗
  2. Affected versionsThe structured affected or fixed version information changed.
    Before
    jQuery: >= 1.0.3, < 3.5.0 · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    jQuery: >= 1.0.3, < 3.5.0 · Fixed: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
    Red Hat Product Security ↗
  3. Affected versionsThe structured affected or fixed version information changed.
    Before
    jQuery: >= 1.0.3, < 3.5.0 · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    jQuery: >= 1.0.3, < 3.5.0 · Fixed: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
    Red Hat Product Security ↗
  4. Affected versionsThe structured affected or fixed version information changed.
    Before
    jQuery: >= 1.0.3, < 3.5.0 · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    jQuery: >= 1.0.3, < 3.5.0 · Fixed: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
    Red Hat Product Security ↗
  5. Affected versionsThe structured affected or fixed version information changed.
    Before
    jQuery: >= 1.0.3, < 3.5.0 · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    jQuery: >= 1.0.3, < 3.5.0 · Fixed: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
    Red Hat Product Security ↗
  6. Affected versionsThe structured affected or fixed version information changed.
    Before
    jQuery: >= 1.0.3, < 3.5.0 · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    jQuery: >= 1.0.3, < 3.5.0 · Fixed: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
    Red Hat Product Security ↗
  7. Vendor guidanceAuthoritative vendor guidance changed: added remediation: oracle.com/cpuApr2021.html; removed remediation: access.redhat.com/CVE-2020-11023.
    Before
    patch: oracle.com/cpuApr2021.html · patch: oracle.com/cpuapr2022.html · patch: oracle.com/cpujan2022.html · 5 more references
    After
    patch: oracle.com/cpuApr2021.html · patch: oracle.com/cpuapr2022.html · patch: oracle.com/cpujan2022.html · 5 more references
    oracle.com ↗
  8. Affected versionsThe structured affected or fixed version information changed.
    Before
    jQuery: >= 1.0.3, < 3.5.0 · Fixed: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
    After
    jQuery: >= 1.0.3, < 3.5.0 · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    CNA ↗
  9. Affected versionsThe structured affected or fixed version information changed.
    Before
    >= 1.0.3, < 3.5.0 · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    jQuery: >= 1.0.3, < 3.5.0 · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    CNA ↗
Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2020-11023 · cve.blacktree.nl