|
210051
|
8.8 |
HIGH
Network
|
dropwizard
|
dropwizard_validation
|
dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability. A server-side template injection was identified in the self-validating feature enabling attackers to …
|
CWE-74
Injection
|
CVE-2020-11002
|
2024-11-21 13:56 |
2020-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210052
|
5.5 |
MEDIUM
Local
|
gitlab
|
gitlab
|
GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.
|
CWE-22
Path Traversal
|
CVE-2020-10977
|
2024-11-21 13:56 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210053
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
GitLab EE/CE 8.17 to 12.9 is vulnerable to information leakage when querying a merge request widget.
|
CWE-200
Information Exposure
|
CVE-2020-10976
|
2024-11-21 13:56 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210054
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab EE/CE 10.8 to 12.9 is leaking metadata and comments on vulnerabilities to unauthorized users on the vulnerability feedback page.
|
NVD-CWE-noinfo
|
CVE-2020-10975
|
2024-11-21 13:56 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210055
|
5.5 |
MEDIUM
Local
|
codeblocks
|
code\
|
A buffer overflow vulnerability in Code::Blocks 17.12 allows an attacker to execute arbitrary code via a crafted project file.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-10814
|
2024-11-21 13:56 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210056
|
6.5 |
MEDIUM
Network
|
greenbrowser_project
|
greenbrowser
|
GreenBrowser before version 1.2 has a vulnerability where apps that rely on URL Parsing to verify that a given URL is pointing to a trust server may be susceptible to many different ways to get URL p…
|
NVD-CWE-Other
|
CVE-2020-11000
|
2024-11-21 13:56 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210057
|
5.6 |
MEDIUM
Network
|
qemu
|
qemu
|
hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not validated against the r/w data length.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-11102
|
2024-11-21 13:56 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210058
|
5.3 |
MEDIUM
Network
|
mediawiki
|
mediawiki
|
In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user interface) to arbitrary DOM nodes via HTML content…
|
CWE-74
Injection
|
CVE-2020-10960
|
2024-11-21 13:56 |
2020-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210059
|
8.8 |
HIGH
Network
|
apachefriends
|
xampp
|
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (includ…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-11107
|
2024-11-21 13:56 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210060
|
8.8 |
HIGH
Network
|
haproxy debian redhat fedoraproject canonical opensuse
|
haproxy debian_linux openshift_container_platform fedora ubuntu_linux leap
|
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-11100
|
2024-11-21 13:56 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|