|
210161
|
9.8 |
CRITICAL
Network
|
ez
|
ez_publish-kernel ez_publish-legacy
|
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to ex…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-10806
|
2024-11-21 13:56 |
2020-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210162
|
5.4 |
MEDIUM
Network
|
phpmyadmin debian fedoraproject opensuse suse
|
phpmyadmin debian_linux fedora leap backports_sle package_hub
|
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results…
|
CWE-79 CWE-89
Cross-site Scripting SQL Injection
|
CVE-2020-10803
|
2024-11-21 13:56 |
2020-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210163
|
8.0 |
HIGH
Network
|
phpmyadmin debian fedoraproject opensuse suse
|
phpmyadmin debian_linux fedora leap backports_sle package_hub
|
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search act…
|
CWE-89
SQL Injection
|
CVE-2020-10802
|
2024-11-21 13:56 |
2020-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210164
|
8.0 |
HIGH
Network
|
phpmyadmin fedoraproject opensuse suse
|
phpmyadmin fedora leap backports_sle package_hub
|
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/Use…
|
CWE-89
SQL Injection
|
CVE-2020-10804
|
2024-11-21 13:56 |
2020-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210165
|
8.1 |
HIGH
Network
|
lix_project
|
lix
|
lix through 15.8.7 allows man-in-the-middle attackers to execute arbitrary code by modifying the HTTP client-server data stream so that the Location header is associated with attacker-controlled exec…
|
NVD-CWE-noinfo
|
CVE-2020-10800
|
2024-11-21 13:56 |
2020-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210166
|
9.8 |
CRITICAL
Network
|
svglib_project
|
svglib
|
The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call.
|
CWE-611
XXE
|
CVE-2020-10799
|
2024-11-21 13:56 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210167
|
7.5 |
HIGH
Network
|
it-novum
|
openitcockpit
|
openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-10792
|
2024-11-21 13:56 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210168
|
8.8 |
HIGH
Network
|
suse
|
rancher
|
In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace to move that namespace to a different project.
|
CWE-863
Incorrect Authorization
|
CVE-2020-10676
|
2024-11-21 13:55 |
2023-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210169
|
8.1 |
HIGH
Network
|
fasterxml oracle
|
jackson-databind retail_merchandising_system retail_sales_audit
|
A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-10650
|
2024-11-21 13:55 |
2022-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210170
|
7.5 |
HIGH
Network
|
python redhat fedoraproject
|
python enterprise_linux software_collections quay fedora
|
A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2020-10735
|
2024-11-21 13:55 |
2022-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|