|
211291
|
5.4 |
MEDIUM
Network
|
strapi
|
strapi
|
Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-27666
|
2024-11-21 14:21 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211292
|
7.5 |
HIGH
Network
|
strapi
|
strapi
|
In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-27665
|
2024-11-21 14:21 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211293
|
9.8 |
CRITICAL
Network
|
strapi
|
strapi
|
admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.
|
NVD-CWE-noinfo
|
CVE-2020-27664
|
2024-11-21 14:21 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211294
|
5.4 |
MEDIUM
Network
|
dedecms
|
dedecms
|
A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web p…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27533
|
2024-11-21 14:21 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211295
|
6.5 |
MEDIUM
Network
|
biscom
|
secure_file_transfer
|
Biscom Secure File Transfer (SFT) before 5.1.1082 and 6.x before 6.0.1011 allows user credential theft.
|
NVD-CWE-noinfo
|
CVE-2020-27646
|
2024-11-21 14:21 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211296
|
3.3 |
LOW
Local
|
imagemagick debian opensuse
|
imagemagick debian_linux leap
|
ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCore/layer.c, which may cause a denial of service.
|
CWE-369
Divide By Zero
|
CVE-2020-27560
|
2024-11-21 14:21 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211297
|
6.1 |
MEDIUM
Network
|
bigbluebutton
|
greenlight
|
A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.
|
CWE-79
Cross-site Scripting
|
CVE-2020-27642
|
2024-11-21 14:21 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211298
|
7.5 |
HIGH
Network
|
fastd_project debian fedoraproject
|
fastd debian_linux fedora
|
receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.
|
CWE-617
Reachable Assertion
|
CVE-2020-27638
|
2024-11-21 14:21 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211299
|
4.3 |
MEDIUM
Network
|
mediawiki
|
mediawiki
|
The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific user's IP address. Instead, for various actions, it would report the IP address …
|
NVD-CWE-Other
|
CVE-2020-27621
|
2024-11-21 14:21 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211300
|
6.1 |
MEDIUM
Network
|
mediawiki
|
skin\
|
The Cosmos Skin for MediaWiki through 1.35.0 has stored XSS because MediaWiki messages were not being properly escaped. This is related to wfMessage and Html::rawElement, as demonstrated by CosmosSoc…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27620
|
2024-11-21 14:21 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|