|
210961
|
7.5 |
HIGH
Network
|
evolutionscript
|
helpdeskz
|
An issue was discovered in HelpDeskZ 1.0.2. The feature to auto-login a user, via the RememberMe functionality, is prone to SQL injection. NOTE: This vulnerability only affects products that are no l…
|
CWE-89
SQL Injection
|
CVE-2020-26546
|
2024-11-21 14:20 |
2020-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210962
|
7.5 |
HIGH
Network
|
pcvuesolutions
|
pcvue
|
ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to access session data of legitimate users. This issue also affects third-party syst…
|
NVD-CWE-noinfo
|
CVE-2020-26869
|
2024-11-21 14:20 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210963
|
7.5 |
HIGH
Network
|
pcvuesolutions
|
pcvue
|
ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitima…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-26868
|
2024-11-21 14:20 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210964
|
9.8 |
CRITICAL
Network
|
pcvuesolutions
|
pcvue
|
ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-e…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-26867
|
2024-11-21 14:20 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210965
|
9.8 |
CRITICAL
Network
|
emby
|
emby
|
Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-26948
|
2024-11-21 14:20 |
2020-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210966
|
7.8 |
HIGH
Local
|
getmonero
|
monero
|
monero-wallet-gui in Monero GUI before 0.17.1.0 includes the . directory in an embedded RPATH (with a preference ahead of /usr/lib), which allows local users to gain privileges via a Trojan horse lib…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-26947
|
2024-11-21 14:20 |
2020-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210967
|
8.1 |
HIGH
Network
|
mybatis
|
mybatis
|
MyBatis before 3.5.6 mishandles deserialization of object streams.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-26945
|
2024-11-21 14:20 |
2020-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210968
|
9.8 |
CRITICAL
Network
|
phpmyadmin opensuse fedoraproject debian
|
phpmyadmin leap backports_sle fedora debian_linux
|
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feat…
|
CWE-89
SQL Injection
|
CVE-2020-26935
|
2024-11-21 14:20 |
2020-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210969
|
6.1 |
MEDIUM
Network
|
phpmyadmin opensuse fedoraproject debian
|
phpmyadmin leap backports_sle fedora debian_linux
|
phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
|
CWE-79
Cross-site Scripting
|
CVE-2020-26934
|
2024-11-21 14:20 |
2020-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210970
|
4.3 |
MEDIUM
Network
|
sympa debian
|
sympa debian_linux
|
debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-26932
|
2024-11-21 14:20 |
2020-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|