|
199841
|
9.8 |
CRITICAL
Network
|
karenderia_multiple_restaurant_system_project
|
karenderia_multiple_restaurant_system
|
A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and below. The vulnerability allows for an unauthenticated attacker to perform various …
|
CWE-89
SQL Injection
|
CVE-2020-28994
|
2024-11-21 14:23 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199842
|
5.5 |
MEDIUM
Local
|
musl-libc debian fedoraproject oracle
|
musl debian_linux fedora graalvm
|
In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow).
|
CWE-787
Out-of-bounds Write
|
CVE-2020-28928
|
2024-11-21 14:23 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199843
|
8.8 |
HIGH
Local
|
xen
|
xen
|
An issue was discovered in Xen through 4.14.x allowing x86 HVM guest OS users to cause a denial of service (stack corruption), cause a data leak, or possibly gain privileges because of an off-by-one …
|
CWE-787 CWE-193
Out-of-bounds Write Off-by-one Error
|
CVE-2020-29040
|
2024-11-21 14:23 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199844
|
6.1 |
MEDIUM
Network
|
seeddms
|
seeddms
|
Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php.
|
CWE-601
Open Redirect
|
CVE-2020-28726
|
2024-11-21 14:23 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199845
|
9.8 |
CRITICAL
Network
|
misp
|
misp
|
MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.
|
CWE-862
Missing Authorization
|
CVE-2020-29006
|
2024-11-21 14:23 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199846
|
5.4 |
MEDIUM
Network
|
mediawiki
|
mediawiki
|
The PollNY extension for MediaWiki through 1.35 allows XSS via an answer option for a poll question, entered during Special:CreatePoll or Special:UpdatePoll.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29003
|
2024-11-21 14:23 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199847
|
4.8 |
MEDIUM
Network
|
mediawiki
|
mediawiki
|
includes/CologneBlueTemplate.php in the CologneBlue skin for MediaWiki through 1.35 allows XSS via a qbfind message supplied by an administrator.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29002
|
2024-11-21 14:23 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199848
|
9.8 |
CRITICAL
Network
|
gitea
|
gitea
|
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_…
|
NVD-CWE-noinfo
|
CVE-2020-28991
|
2024-11-21 14:23 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199849
|
9.8 |
CRITICAL
Network
|
spip debian
|
spip debian_linux
|
prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.
|
NVD-CWE-noinfo
|
CVE-2020-28984
|
2024-11-21 14:23 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199850
|
6.1 |
MEDIUM
Network
|
magicpin
|
magicpin
|
There is a Stored XSS in Magicpin v2.1 in the User Registration section. Each time an admin visits the manage user section from the admin panel, the XSS triggers and the attacker can able to steal th…
|
CWE-79
Cross-site Scripting
|
CVE-2020-28927
|
2024-11-21 14:23 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|