|
210551
|
9.8 |
CRITICAL
Network
|
typo3
|
mediace
|
In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification mechanism can be used to generate arbitrary check…
|
NVD-CWE-Other
|
CVE-2020-15086
|
2024-11-21 14:04 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210552
|
4.9 |
MEDIUM
Network
|
ihatemoney
|
i_hate_money
|
In "I hate money" before version 4.1.5, an authenticated member of one project can modify and delete members of another project, without knowledge of this other project's private code. This can be fu…
|
CWE-863
Incorrect Authorization
|
CVE-2020-15120
|
2024-11-21 14:04 |
2020-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210553
|
3.5 |
LOW
Network
|
freerdp fedoraproject opensuse canonical debian
|
freerdp fedora leap ubuntu_linux debian_linux
|
In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. All FreeRDP clients are affected. The input rectangles from the server are not c…
|
-
|
CVE-2020-15103
|
2024-11-21 14:04 |
2020-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210554
|
6.5 |
MEDIUM
Network
|
parseplatform
|
parse_server
|
In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User object and can also by pass all objects linked via…
|
CWE-863
Incorrect Authorization
|
CVE-2020-15126
|
2024-11-21 14:04 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210555
|
6.5 |
MEDIUM
Network
|
intranda
|
goobi_viewer_core
|
In Goobi Viewer Core before version 4.8.3, a path traversal vulnerability allows for remote attackers to access files on the server via the application. This is limited to files accessible to the app…
|
CWE-22
Path Traversal
|
CVE-2020-15124
|
2024-11-21 14:04 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210556
|
6.5 |
MEDIUM
Network
|
prestashop
|
dashboard_products
|
In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to change the configuration. The problem is fixed in 2.1.0.
|
CWE-862
Missing Authorization
|
CVE-2020-15102
|
2024-11-21 14:04 |
2020-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210557
|
9.6 |
CRITICAL
Network
|
radare fedoraproject
|
radare2 fedora
|
In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger …
|
CWE-78
OS Command
|
CVE-2020-15121
|
2024-11-21 14:04 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210558
|
6.1 |
MEDIUM
Network
|
articatech
|
artica_proxy
|
An issue was discovered in Artica Proxy CE before 4.28.030.418. Reflected XSS exists via these search fields: real time request, System Events, Proxy Events, Proxy Objects, and Firewall objects.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15053
|
2024-11-21 14:04 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210559
|
7.5 |
HIGH
Network
|
articatech
|
artica_proxy
|
An issue was discovered in Artica Proxy CE before 4.28.030.418. SQL Injection exists via the Netmask, Hostname, and Alias fields.
|
CWE-89
SQL Injection
|
CVE-2020-15052
|
2024-11-21 14:04 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210560
|
9.3 |
CRITICAL
Network
|
codecov
|
codecov
|
In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the codecov-node library are unlikely to be aware of this, so they might unwittingly …
|
CWE-78
OS Command
|
CVE-2020-15123
|
2024-11-21 14:04 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|