|
199701
|
5.3 |
MEDIUM
Network
|
sesame-system
|
web-sesame
|
A misconfiguration in Web-Sesame 2020.1.1.3375 allows an unauthenticated attacker to download the source code of the application, facilitating its comprehension (code review). Specifically, JavaScrip…
|
NVD-CWE-noinfo
|
CVE-2020-29041
|
2024-11-21 14:23 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199702
|
5.5 |
MEDIUM
Local
|
drivergenius
|
drivergenius_firmware
|
MyDrivers64.sys in DriverGenius 9.61.3708.3054 allows attackers to cause a system crash via the ioctl command 0x9c402000 to \\.\MyDrivers0_0_1.
|
NVD-CWE-noinfo
|
CVE-2020-28841
|
2024-11-21 14:23 |
2021-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199703
|
7.5 |
HIGH
Network
|
golang
|
text
|
In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. (x/text/language is supposed to be able to parse an HTTP Accep…
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-28852
|
2024-11-21 14:23 |
2021-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199704
|
7.5 |
HIGH
Network
|
golang
|
go
|
In x/text in Go 1.15.4, an "index out of range" panic occurs in language.ParseAcceptLanguage while parsing the -u- extension. (x/text/language is supposed to be able to parse an HTTP Accept-Language …
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-28851
|
2024-11-21 14:23 |
2021-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199705
|
5.4 |
MEDIUM
Network
|
egavilanmedia
|
user_registration_and_login_system_with_admin_panel
|
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the attacker injecting the …
|
CWE-79
Cross-site Scripting
|
CVE-2020-29231
|
2024-11-21 14:23 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199706
|
6.1 |
MEDIUM
Network
|
egavilanmedia
|
user_registration_and_login_system_with_admin_panel
|
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab using the Full Name of the user. This vulnerabilit…
|
CWE-79
Cross-site Scripting
|
CVE-2020-29230
|
2024-11-21 14:23 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199707
|
7.5 |
HIGH
Network
|
egavilanmedia
|
user_registration_and_login_system_with_admin_panel
|
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.
|
CWE-89
SQL Injection
|
CVE-2020-29228
|
2024-11-21 14:23 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199708
|
5.3 |
MEDIUM
Network
|
boltcms
|
bolt
|
Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How to Harden Your PHP for Better Security" guidance.
|
NVD-CWE-noinfo
|
CVE-2020-28925
|
2024-11-21 14:23 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199709
|
8.8 |
HIGH
Network
|
plone
|
plone
|
Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role).
|
CWE-611
XXE
|
CVE-2020-28736
|
2024-11-21 14:23 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199710
|
8.8 |
HIGH
Network
|
plone
|
plone
|
Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-28735
|
2024-11-21 14:23 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|