|
210231
|
6.1 |
MEDIUM
Network
|
usvn
|
user-friendly_svn
|
USVN (aka User-friendly SVN) before 1.0.9 allows XSS via SVN logs.
|
CWE-79
Cross-site Scripting
|
CVE-2020-17364
|
2024-11-21 14:07 |
2020-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210232
|
9.8 |
CRITICAL
Network
|
lilypond fedoraproject debian opensuse
|
lilypond fedora debian_linux leap backports_sle
|
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous …
|
NVD-CWE-noinfo
|
CVE-2020-17353
|
2024-11-21 14:07 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210233
|
8.1 |
HIGH
Network
|
pghero_project
|
pghero
|
The PgHero gem through 2.6.0 for Ruby allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-16253
|
2024-11-21 14:07 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210234
|
4.3 |
MEDIUM
Network
|
field_test_project
|
field_test
|
The Field Test gem 0.2.0 through 0.3.2 for Ruby allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-16252
|
2024-11-21 14:07 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210235
|
6.1 |
MEDIUM
Network
|
extremenetworks
|
extreme_management_center
|
Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in a GET request, aka CFD-4887.
|
CWE-79
Cross-site Scripting
|
CVE-2020-16847
|
2024-11-21 14:07 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210236
|
5.9 |
MEDIUM
Network
|
amazon
|
firecracker
|
In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. This can result in a denial of service on the microVM when it is configured wit…
|
NVD-CWE-noinfo
|
CVE-2020-16843
|
2024-11-21 14:07 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210237
|
9.1 |
CRITICAL
Network
|
kee
|
keepassrpc
|
The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 is missing validation for a client-provided parameter, which allows remote attackers to read and modify data in the KeePass database vi…
|
CWE-20
Improper Input Validation
|
CVE-2020-16272
|
2024-11-21 14:07 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210238
|
9.1 |
CRITICAL
Network
|
kee
|
keepassrpc
|
The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 generates insufficiently random numbers, which allows remote attackers to read and modify data in the KeePass database via a WebSocket …
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-16271
|
2024-11-21 14:07 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210239
|
5.5 |
MEDIUM
Local
|
radare fedoraproject
|
radare2 fedora
|
radare2 4.5.0 misparses DWARF information in executable files, causing a segmentation fault in parse_typedef in type_dwarf.c via a malformed DW_AT_name in the .debug_info section.
|
NVD-CWE-noinfo
|
CVE-2020-16269
|
2024-11-21 14:07 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210240
|
8.8 |
HIGH
Network
|
mozilla
|
thunderbird
|
During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. This vulnerability affects Thunderbird < 78.7.
|
CWE-77
Command Injection
|
CVE-2020-15685
|
2024-11-21 14:06 |
2022-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|