|
209691
|
7.5 |
HIGH
Network
|
lionwiki
|
lionwiki
|
LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted string in the index.php f1 variable, aka Local File Inclusion. NOTE: This vulnerability only aff…
|
NVD-CWE-noinfo
|
CVE-2020-27191
|
2024-11-21 14:20 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209692
|
7.5 |
HIGH
Network
|
eclipse
|
hono
|
In Eclipse Hono version 1.3.0 and 1.4.0 the AMQP protocol adapter does not verify the size of AMQP messages received from devices. In particular, a device may send messages that are bigger than the m…
|
NVD-CWE-noinfo
|
CVE-2020-27217
|
2024-11-21 14:20 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209693
|
6.1 |
MEDIUM
Network
|
sap
|
fiori_launchpad_\(news_tile_application\)
|
SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to use SAP Fiori Launchpad News tile Application to send malicious code, to a differen…
|
CWE-79
Cross-site Scripting
|
CVE-2020-26825
|
2024-11-21 14:20 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209694
|
6.1 |
MEDIUM
Network
|
ckeditor oracle
|
ckeditor banking_platform peoplesoft_enterprise_peopletools agile_plm commerce_merchandising jd_edwards_enterpriseone_tools financial_services_analytical_applications_infrastructure…
|
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML co…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27193
|
2024-11-21 14:20 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209695
|
7.2 |
HIGH
Network
|
sapplica
|
sentrifugo
|
In Sentrifugo 3.2, admin can edit employee's informations via this endpoint --> /sentrifugo/index.php/empadditionaldetails/edit/userid/2. In this POST request, "employeeNumId" parameter is affected b…
|
CWE-89
SQL Injection
|
CVE-2020-26805
|
2024-11-21 14:20 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209696
|
8.8 |
HIGH
Network
|
sapplica
|
sentrifugo
|
In Sentrifugo 3.2, users can share an announcement under "Organization -> Announcements" tab. Also, in this page, users can upload attachments with the shared announcements. This "Upload Attachment" …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-26804
|
2024-11-21 14:20 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209697
|
8.8 |
HIGH
Network
|
sapplica
|
sentrifugo
|
In Sentrifugo 3.2, users can upload an image under "Assets -> Add" tab. This "Upload Images" functionality is suffered from "Unrestricted File Upload" vulnerability so attacker can upload malicious f…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-26803
|
2024-11-21 14:20 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209698
|
10.0 |
CRITICAL
Network
|
sap
|
solution_manager
|
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Legacy Ports Service, this has an…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-26824
|
2024-11-21 14:20 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209699
|
8.8 |
HIGH
Network
|
tibco
|
iprocess_workspace_browser
|
The Core component of TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser) contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a Cross Si…
|
CWE-352
Origin Validation Error
|
CVE-2020-27146
|
2024-11-21 14:20 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209700
|
10.0 |
CRITICAL
Network
|
sap
|
solution_manager
|
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Diagnostics Agent Connection Serv…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-26823
|
2024-11-21 14:20 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|