|
196811
|
5.3 |
MEDIUM
Network
|
parseplatform
|
parse-server
|
In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the NoSQL, you can use a regex on sessionToken and find valid accounts this way.
|
CWE-863
Incorrect Authorization
|
CVE-2020-5251
|
2024-11-21 14:33 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196812
|
6.5 |
MEDIUM
Network
|
puma
|
puma
|
In Puma (RubyGem) before 4.3.3 and 3.12.4, if an application using Puma allows untrusted input in an early-hints header, an attacker can use a carriage return character to end the header and inject m…
|
CWE-74
Injection
|
CVE-2020-5249
|
2024-11-21 14:33 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196813
|
7.5 |
HIGH
Network
|
ruby-lang puma debian fedoraproject
|
ruby puma debian_linux fedora
|
In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response header, an attacker can use newline characters (i.e. `CR`, `LF` or`/r`, `/n`) to en…
|
-
|
CVE-2020-5247
|
2024-11-21 14:33 |
2020-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196814
|
8.8 |
HIGH
Network
|
dropwizard oracle
|
dropwizard_validation blockchain_platform
|
Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Lan…
|
CWE-74
Injection
|
CVE-2020-5245
|
2024-11-21 14:33 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196815
|
7.5 |
HIGH
Network
|
buddypress
|
buddypress
|
In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. This has been patched in version 5.1.2.
|
CWE-200
Information Exposure
|
CVE-2020-5244
|
2024-11-21 14:33 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196816
|
6.5 |
MEDIUM
Network
|
dnnsoftware
|
dotnetnuke
|
DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
|
CWE-669 CWE-434
Incorrect Resource Transfer Between Spheres Unrestricted Upload of File with Dangerous Type
|
CVE-2020-5188
|
2024-11-21 14:33 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196817
|
8.8 |
HIGH
Network
|
dnnsoftware
|
dotnetnuke
|
DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).
|
CWE-22
Path Traversal
|
CVE-2020-5187
|
2024-11-21 14:33 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196818
|
5.4 |
MEDIUM
Network
|
dnnsoftware
|
dotnetnuke
|
DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).
|
CWE-79
Cross-site Scripting
|
CVE-2020-5186
|
2024-11-21 14:33 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196819
|
7.5 |
HIGH
Network
|
uap-core_project
|
uap-core
|
uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regexes are vulnerable to regular expression denial of service (REDoS) due to overla…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2020-5243
|
2024-11-21 14:33 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196820
|
8.8 |
HIGH
Network
|
openhab
|
openhab
|
openHAB before 2.5.2 allow a remote attacker to use REST calls to install the EXEC binding or EXEC transformation service and execute arbitrary commands on the system with the privileges of the user …
|
CWE-863
Incorrect Authorization
|
CVE-2020-5242
|
2024-11-21 14:33 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|