|
211341
|
6.1 |
MEDIUM
Network
|
typo3
|
fluid_engine typo3
|
TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vulnerable to cross-site scripting when making use of the ternary conditional oper…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15241
|
2024-11-21 14:05 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211342
|
6.1 |
MEDIUM
Network
|
vercel
|
next.js
|
Next.js versions >=9.5.0 and <9.5.4 are vulnerable to an Open Redirect. Specially encoded paths could be used with the trailing slash redirect to allow an open redirect to occur to an external site. …
|
-
|
CVE-2020-15242
|
2024-11-21 14:05 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211343
|
5.9 |
MEDIUM
Network
|
mozilla
|
thunderbird
|
If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunde…
|
NVD-CWE-noinfo
|
CVE-2020-15646
|
2024-11-21 14:05 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211344
|
6.5 |
MEDIUM
Network
|
smarter
|
smarter_coffee_maker_1st_generation
|
Smarter Coffee Maker before 2nd generation allows firmware replacement without authentication or authorization. User interaction is required to press a button. NOTE: This vulnerability only affects p…
|
NVD-CWE-noinfo
|
CVE-2020-15501
|
2024-11-21 14:05 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211345
|
5.3 |
MEDIUM
Network
|
glpi-project
|
glpi
|
In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in version 9.5.0 and patched in 9.5.2. As a workaround, disable public access to …
|
-
|
CVE-2020-15217
|
2024-11-21 14:05 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211346
|
8.6 |
HIGH
Network
|
glpi-project
|
glpi
|
In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does not escape or sanitize allowing for SQL Injection to occur. Leveraging this vulne…
|
-
|
CVE-2020-15176
|
2024-11-21 14:05 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211347
|
4.3 |
MEDIUM
Network
|
glpi-project
|
glpi
|
In GLPI before version 9.5.2, there is a SQL Injection in the API's search function. Not only is it possible to break the SQL syntax, but it is also possible to utilise a UNION SELECT query to reflec…
|
-
|
CVE-2020-15226
|
2024-11-21 14:05 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211348
|
6.1 |
MEDIUM
Network
|
glpi-project
|
glpi
|
In GLPI before version 9.5.2, the `install/install.php` endpoint insecurely stores user input into the database as `url_base` and `url_base_api`. These settings are referenced throughout the applicat…
|
-
|
CVE-2020-15177
|
2024-11-21 14:05 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211349
|
9.1 |
CRITICAL
Network
|
glpi-project
|
glpi
|
In GLPI before version 9.5.2, the `?pluginimage.send.php?` endpoint allows a user to specify an image from a plugin. The parameters can be maliciously crafted to instead delete the .htaccess file for…
|
-
|
CVE-2020-15175
|
2024-11-21 14:05 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211350
|
3.5 |
LOW
Network
|
xmpp-http-upload_project
|
xmpp-http-upload
|
In xmpp-http-upload before version 0.4.0, when the GET method is attacked, attackers can read files which have a `.data` suffix and which are accompanied by a JSON file with the `.meta` suffix. This …
|
-
|
CVE-2020-15239
|
2024-11-21 14:05 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|