|
210231
|
7.8 |
HIGH
Local
|
freebsd
|
freebsd
|
grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, mishandles font loading by a guest through a grub2.cfg file, leading to a buffer overflow.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-10566
|
2024-11-21 13:55 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210232
|
7.8 |
HIGH
Local
|
freebsd
|
freebsd
|
grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, does not validate the address provided as part of a memrw command (read_* or write_*) by a guest through a grub2.cfg file. Thi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-10565
|
2024-11-21 13:55 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210233
|
9.8 |
CRITICAL
Network
|
iptanus
|
wordpress_file_upload
|
An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because …
|
CWE-22
Path Traversal
|
CVE-2020-10564
|
2024-11-21 13:55 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210234
|
9.8 |
CRITICAL
Network
|
devome
|
grr
|
An issue was discovered in DEVOME GRR before 3.4.1c. frmcontactlist.php mishandles a SQL query.
|
CWE-89
SQL Injection
|
CVE-2020-10563
|
2024-11-21 13:55 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210235
|
7.2 |
HIGH
Network
|
devome
|
grr
|
An issue was discovered in DEVOME GRR before 3.4.1c. admin_edit_room.php mishandles file uploads.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-10562
|
2024-11-21 13:55 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210236
|
6.1 |
MEDIUM
Network
|
primetek
|
primefaces
|
An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, an attacker can provide JavaScript code in an input field whose data is later u…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10544
|
2024-11-21 13:55 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210237
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_opmanager
|
Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. This was fixed in 12.5.108.
|
NVD-CWE-noinfo
|
CVE-2020-10541
|
2024-11-21 13:55 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210238
|
8.8 |
HIGH
Network
|
untis
|
webuntis
|
Untis WebUntis before 2020.9.6 allows CSRF for certain combinations of rights and modules.
|
CWE-352
Origin Validation Error
|
CVE-2020-10540
|
2024-11-21 13:55 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210239
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.
|
NVD-CWE-noinfo
|
CVE-2020-10535
|
2024-11-21 13:55 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210240
|
9.8 |
CRITICAL
Network
|
mediawiki
|
mediawiki
|
In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges. This is related to t…
|
CWE-863
Incorrect Authorization
|
CVE-2020-10534
|
2024-11-21 13:55 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|