|
210061
|
7.8 |
HIGH
Local
|
deltaww
|
cncsoft_screeneditor
|
Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. An uninitialized pointer may be exploited by processing a specially crafted project file. Successful exploitation of this…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2020-16203
|
2024-11-21 14:06 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210062
|
3.3 |
LOW
Local
|
deltaww
|
cncsoft_screeneditor
|
Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple out-of-bounds read vulnerabilities may be exploited by processing specially crafted project files, which may all…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-16201
|
2024-11-21 14:06 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210063
|
7.8 |
HIGH
Local
|
deltaww
|
cncsoft_screeneditor
|
Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, whic…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-16199
|
2024-11-21 14:06 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210064
|
8.0 |
HIGH
Adjacent
|
swisscom
|
internet-box_2_firmware internet-box_standard_firmware internet-box_plus_firmware internet-box_3_firmware internet-box_light_firmware
|
An issue was discovered on Swisscom Internet Box 2, Internet Box Standard, Internet Box Plus prior to 10.04.38, Internet Box 3 prior to 11.01.20, and Internet Box light prior to 08.06.06. Given the (…
|
NVD-CWE-noinfo
|
CVE-2020-16134
|
2024-11-21 14:06 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210065
|
3.3 |
LOW
Local
|
kde debian fedoraproject opensuse canonical
|
ark debian_linux fedora leap ubuntu_linux
|
In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.
|
CWE-22
Path Traversal
|
CVE-2020-16116
|
2024-11-21 14:06 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210066
|
6.1 |
MEDIUM
Network
|
tiki
|
tiki
|
Tiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-16131
|
2024-11-21 14:06 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210067
|
8.8 |
HIGH
Network
|
sonatype
|
nexus_repository_manager_3
|
Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.
|
NVD-CWE-noinfo
|
CVE-2020-15871
|
2024-11-21 14:06 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210068
|
6.1 |
MEDIUM
Network
|
sonatype
|
nexus_repository_manager_3
|
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2).
|
CWE-79
Cross-site Scripting
|
CVE-2020-15870
|
2024-11-21 14:06 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210069
|
5.4 |
MEDIUM
Network
|
sonatype
|
nexus_repository_manager_3
|
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).
|
CWE-79
Cross-site Scripting
|
CVE-2020-15869
|
2024-11-21 14:06 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210070
|
7.7 |
HIGH
Network
|
tgstation13
|
tgstation-server
|
In tgstation-server 4.4.0 and 4.4.1, an authenticated user with permission to download logs can download any file on the server machine (accessible by the owner of the server process) via directory t…
|
CWE-22
Path Traversal
|
CVE-2020-16136
|
2024-11-21 14:06 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|