|
210041
|
7.5 |
HIGH
Network
|
winmail_project
|
winmail
|
A SSRF vulnerability exists in Winmail 6.5 in app.php in the key parameter when HTTPS is on. An attacker can use this vulnerability to cause the server to send a request to a specific URL. An attacke…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-23776
|
2024-11-21 14:14 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210042
|
6.1 |
MEDIUM
Network
|
winmail_project
|
winmail
|
A reflected XSS vulnerability exists in tohtml/convert.php of Winmail 6.5, which can cause JavaScript code to be executed.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23774
|
2024-11-21 14:14 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210043
|
8.8 |
HIGH
Network
|
openmaint
|
openmaint
|
openMAINT before 1.1-2.4.2 allows remote authenticated users to run arbitrary JSP code on the underlying web server.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-24549
|
2024-11-21 14:14 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210044
|
6.1 |
MEDIUM
Network
|
misp
|
misp
|
A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function. Due to a lack of controller validation in "path" parameter, …
|
CWE-79
Cross-site Scripting
|
CVE-2020-24085
|
2024-11-21 14:14 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210045
|
8.8 |
HIGH
Network
|
assaabloy
|
yale_wipc-303w_firmware
|
The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API. NOTE: This may be a duplicate of CVE-2020-10176
|
CWE-78
OS Command
|
CVE-2020-23826
|
2024-11-21 14:14 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210046
|
9.8 |
CRITICAL
Network
|
live555
|
liblivemedia
|
In Live Networks, Inc., liblivemedia version 20200625, there is a potential buffer overflow bug in the server handling of a RTSP "PLAY" command, when the command specifies seeking by absolute time.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-24027
|
2024-11-21 14:14 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210047
|
5.3 |
MEDIUM
Network
|
sass-lang
|
node-sass
|
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-24025
|
2024-11-21 14:14 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210048
|
3.3 |
LOW
Local
|
microsoft
|
skype
|
Microsoft Skype through 8.59.0.77 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access …
|
NVD-CWE-noinfo
|
CVE-2020-24003
|
2024-11-21 14:14 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210049
|
8.8 |
HIGH
Network
|
fork-cms
|
fork_cms
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Fork before 5.8.3 allows remote attackers to perform unauthorized actions as administrator to (1) approve the mass o…
|
CWE-352
Origin Validation Error
|
CVE-2020-23960
|
2024-11-21 14:14 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210050
|
6.1 |
MEDIUM
Network
|
jsoneditoronline
|
jsoneditor
|
Stored XSS was discovered in the tree mode of jsoneditor before 9.0.2 through injecting and executing JavaScript.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23849
|
2024-11-21 14:14 |
2021-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|