|
209721
|
5.3 |
MEDIUM
Network
|
postfix
|
postfix
|
A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demonstrated by the similarity of \xce\xbf to the 'o' character…
|
NVD-CWE-Other
|
CVE-2020-12063
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209722
|
6.1 |
MEDIUM
Network
|
app2pro
|
airdisk_pro
|
The AirDisk Pro app 5.5.3 for iOS allows XSS via the deleteFile parameter of the Delete function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12130
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209723
|
6.1 |
MEDIUM
Network
|
app2pro
|
airdisk_pro
|
The AirDisk Pro app 5.5.3 for iOS allows XSS via the createFolder parameter of the Create Folder function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12129
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209724
|
7.5 |
HIGH
Network
|
file_transfer_ifamily_project
|
file_transfer_ifamily
|
DONG JOO CHO File Transfer iFamily 2.1 allows directory traversal related to the ./etc/ path.
|
CWE-22
Path Traversal
|
CVE-2020-12128
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209725
|
8.2 |
HIGH
Network
|
binance
|
tss-lib
|
The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a signing round or obtain sensitive information fro…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-12118
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209726
|
6.1 |
MEDIUM
Network
|
bigbluebutton
|
bigbluebutton
|
BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12113
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209727
|
7.5 |
HIGH
Network
|
bigbluebutton
|
bigbluebutton
|
BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.
|
CWE-22
Path Traversal
|
CVE-2020-12112
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209728
|
5.9 |
MEDIUM
Network
|
infradead opensuse
|
openconnect leap
|
OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers in performing man-in-the-middle attacks.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-12105
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209729
|
6.1 |
MEDIUM
Network
|
catchplugins
|
catch_breadcrumb
|
The Catch Breadcrumb plugin before 1.5.4 for WordPress allows Reflected XSS via the s parameter (a search query). Also affected are 16 themes (if the plugin is enabled) by the same author: Alchemist …
|
CWE-79
Cross-site Scripting
|
CVE-2020-12054
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209730
|
10.0 |
CRITICAL
Network
|
beakerbrowser
|
beaker
|
Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-p…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-12079
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|