|
209291
|
6.1 |
MEDIUM
Network
|
projectworlds
|
visitor_management_system_in_php
|
Projectworlds Visitor Management System in PHP 1.0 allows XSS. The file myform.php does not perform input validation on the request parameters. An attacker can inject javascript payloads in the param…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25761
|
2024-11-21 14:18 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209292
|
8.8 |
HIGH
Network
|
projectworlds
|
visitor_management_system_in_php
|
Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid' parameter. An attacker can append SQL queries to the input t…
|
CWE-89
SQL Injection
|
CVE-2020-25760
|
2024-11-21 14:18 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209293
|
6.3 |
MEDIUM
Local
|
trendmicro
|
antivirus\+_2020 internet_security_2020 maximum_security_2020 premium_security_2020
|
The Trend Micro Security 2020 (v16) consumer family of products is vulnerable to a security race condition arbitrary file deletion vulnerability that could allow an unprivileged user to manipulate th…
|
CWE-362
Race Condition
|
CVE-2020-25775
|
2024-11-21 14:18 |
2020-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209294
|
4.3 |
MEDIUM
Network
|
trendmicro
|
apex_one
|
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to trigger an out-of-bounds red information disclosure which would disclose sensitive information to …
|
CWE-125
Out-of-bounds Read
|
CVE-2020-25774
|
2024-11-21 14:18 |
2020-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209295
|
7.8 |
HIGH
Local
|
trendmicro
|
apex_one
|
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to execute arbitrary code on affected products. User interaction is required to exploit this vulnerab…
|
CWE-415
Double Free
|
CVE-2020-25773
|
2024-11-21 14:18 |
2020-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209296
|
5.5 |
MEDIUM
Local
|
trendmicro
|
apex_one
|
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installation…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-25772
|
2024-11-21 14:18 |
2020-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209297
|
5.5 |
MEDIUM
Local
|
trendmicro
|
apex_one
|
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installation…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-25771
|
2024-11-21 14:18 |
2020-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209298
|
5.5 |
MEDIUM
Local
|
trendmicro
|
apex_one
|
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installation…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-25770
|
2024-11-21 14:18 |
2020-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209299
|
7.5 |
HIGH
Network
|
mediawiki fedoraproject
|
mediawiki fedora
|
An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. Handling of actor ID does not necessarily use the correct database or correct wiki.
|
CWE-863
Incorrect Authorization
|
CVE-2020-25869
|
2024-11-21 14:18 |
2020-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209300
|
7.5 |
HIGH
Network
|
mediawiki fedoraproject
|
mediawiki fedora
|
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limit…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-25827
|
2024-11-21 14:18 |
2020-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|