|
209111
|
8.1 |
HIGH
Network
|
sylabs opensuse
|
singularity leap
|
Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-25039
|
2024-11-21 14:16 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209112
|
6.5 |
MEDIUM
Network
|
genexis
|
platinum_4410_firmware
|
A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices was found to be vulnerable to Broken Access Control …
|
CWE-352
Origin Validation Error
|
CVE-2020-25015
|
2024-11-21 14:16 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209113
|
5.5 |
MEDIUM
Local
|
libraw
|
libraw
|
libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs on…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-24890
|
2024-11-21 14:16 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209114
|
7.8 |
HIGH
Local
|
libraw
|
libraw
|
A buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedModel in src/metadata/normalize_model.cpp may lead to context-dependent arbitrary code execution.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-24889
|
2024-11-21 14:16 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209115
|
7.5 |
HIGH
Network
|
elkarbackup
|
elkarbackup
|
A Sensitive Source Code Path Disclosure vulnerability is found in ElkarBackup v1.3.3. An attacker is able to view the path of the source code jobs/sort where entire source code path is displayed in t…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-24925
|
2024-11-21 14:16 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209116
|
5.4 |
MEDIUM
Network
|
elkarbackup
|
elkarbackup
|
A Persistent Cross-site Scripting vulnerability is found in ElkarBackup v1.3.3, where an attacker can steal the user session cookie using this vulnerability present on Policies >> action >> Name Para…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24924
|
2024-11-21 14:16 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209117
|
9.8 |
CRITICAL
Network
|
yaws debian canonical
|
yaws debian_linux ubuntu_linux
|
CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
|
CWE-78
OS Command
|
CVE-2020-24916
|
2024-11-21 14:16 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209118
|
6.1 |
MEDIUM
Network
|
kentico
|
kentico
|
Cross Site Scripting (XSS) vulnerability in Kentico before 12.0.75.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24794
|
2024-11-21 14:16 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209119
|
9.8 |
CRITICAL
Network
|
tendacn
|
ac18_firmware
|
Tenda AC18 Router through V15.03.05.05_EN and through V15.03.05.19(6318) CN devices could cause a remote code execution due to incorrect authentication handling of vulnerable logincheck() function in…
|
CWE-287
Improper Authentication
|
CVE-2020-24987
|
2024-11-21 14:16 |
2020-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209120
|
7.2 |
HIGH
Network
|
concretecms
|
concrete_cms
|
Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to modify site configuration to upload the PHP file and…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-24986
|
2024-11-21 14:16 |
2020-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|