|
209981
|
4.8 |
MEDIUM
Network
|
requarks
|
wiki.js
|
In Wiki.js before 2.3.81, there is a stored XSS in the Markdown editor. An editor with write access to a page, using the Markdown editor, could inject an XSS payload into the content. If another edit…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11051
|
2024-11-21 13:56 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209982
|
5.3 |
MEDIUM
Network
|
ruby-lang fedoraproject debian
|
ruby fedora debian_linux
|
An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buffer, exception: false), the method resizes the buff…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2020-10933
|
2024-11-21 13:56 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209983
|
7.5 |
HIGH
Network
|
oklok_project
|
oklok
|
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwor…
|
CWE-613 CWE-307
Insufficient Session Expiration mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-10876
|
2024-11-21 13:56 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209984
|
4.7 |
MEDIUM
Local
|
torchbox
|
wagtail
|
In Wagtail before versions 2.7.3 and 2.8.2, a potential timing attack exists on pages or documents that have been protected with a shared password through Wagtail's "Privacy" controls. This password …
|
CWE-362
Race Condition
|
CVE-2020-11037
|
2024-11-21 13:56 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209985
|
5.4 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11030
|
2024-11-21 13:56 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209986
|
6.1 |
MEDIUM
Network
|
debian wordpress
|
debian_linux wordpress
|
In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scripting (XSS) attacks. This has been patched in version …
|
CWE-79
Cross-site Scripting
|
CVE-2020-11029
|
2024-11-21 13:56 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209987
|
7.5 |
HIGH
Network
|
wordpress debian
|
wordpress debian_linux
|
In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-11028
|
2024-11-21 13:56 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209988
|
8.1 |
HIGH
Network
|
debian wordpress
|
debian_linux wordpress
|
In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious part…
|
-
|
CVE-2020-11027
|
2024-11-21 13:56 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209989
|
5.4 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user wit…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11026
|
2024-11-21 13:56 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209990
|
8.8 |
HIGH
Network
|
intelmq_manager_project
|
intelmq_manager
|
IntelMQ Manager from version 1.1.0 and before version 2.1.1 has a vulnerability where the backend incorrectly handled messages given by user-input in the "send" functionality of the Inspect-tool of t…
|
CWE-78
OS Command
|
CVE-2020-11016
|
2024-11-21 13:56 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|