|
210661
|
7.5 |
HIGH
Network
|
yubico
|
yubikey_one_time_password_validation_server
|
The verify endpoint in YubiKey Validation Server before 2.40 does not check the length of SQL queries, which allows remote attackers to cause a denial of service, aka SQL injection. NOTE: this issue …
|
CWE-89
SQL Injection
|
CVE-2020-10184
|
2024-11-21 13:54 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210662
|
9.8 |
CRITICAL
Network
|
eset
|
nod32_antivirus smart_security mobile_security smart_tv_security cyber_security
|
The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antiviru…
|
CWE-436
Interpretation Conflict
|
CVE-2020-10180
|
2024-11-21 13:54 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210663
|
7.0 |
HIGH
Local
|
timeshift_project fedoraproject canonical
|
timeshift fedora ubuntu_linux
|
init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the predictable location /tmp/timeshift. It follows symlinks in this location or uses…
|
CWE-362 CWE-59
Race Condition Link Following
|
CVE-2020-10174
|
2024-11-21 13:54 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210664
|
8.8 |
HIGH
Network
|
comtrend
|
vr-3033_firmware
|
Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstrated by shell metac…
|
CWE-78
OS Command
|
CVE-2020-10173
|
2024-11-21 13:54 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210665
|
5.4 |
MEDIUM
Network
|
phpgurukul
|
daily_expense_tracker_system
|
PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS, as demonstrated by the ExpenseItem or ExpenseCost parameter in manage-expense.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10107
|
2024-11-21 13:54 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210666
|
9.8 |
CRITICAL
Network
|
phpgurukul
|
daily_expense_tracker_system
|
PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to SQL injection, as demonstrated by the email parameter in index.php or register.php. The SQL injection allows to dump the MySQL database an…
|
CWE-89
SQL Injection
|
CVE-2020-10106
|
2024-11-21 13:54 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210667
|
5.3 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET request. Disclosure of source code allows for an at…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2020-10105
|
2024-11-21 13:54 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210668
|
4.3 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad 3.0 through 3.2. After authentication, it transmits sensitive information to the user that may be compromised and used by an attacker to gain unauthorized access. Ha…
|
CWE-200
Information Exposure
|
CVE-2020-10104
|
2024-11-21 13:54 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210669
|
5.4 |
MEDIUM
Network
|
zammad
|
zammad
|
An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the File Upload functionality in Zammad. The malicious JavaScript will execute w…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10103
|
2024-11-21 13:54 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210670
|
7.5 |
HIGH
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad 3.0 through 3.2. The WebSocket server crashes when messages in non-JSON format are sent by an attacker. The message format is not properly checked and parsing errors…
|
CWE-20 CWE-755
Improper Input Validation Improper Handling of Exceptional Conditions
|
CVE-2020-10101
|
2024-11-21 13:54 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|