|
196761
|
9.8 |
CRITICAL
Network
|
vaaip
|
freelancy
|
Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"application/x-php"} to the /api/files/ URI.
|
CWE-78
OS Command
|
CVE-2020-5505
|
2024-11-21 14:34 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196762
|
5.4 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
In BIG-IP APM portal access on versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, when backend servers serve HTTP pages with special JavaScript code, this c…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5853
|
2024-11-21 14:34 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196763
|
7.5 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
Undisclosed traffic patterns received may cause a disruption of service to the Traffic Management Microkernel (TMM). This vulnerability affects TMM through a virtual server configured with a FastL4 p…
|
NVD-CWE-noinfo
|
CVE-2020-5852
|
2024-11-21 14:34 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196764
|
4.6 |
MEDIUM
Physics
|
f5
|
big-ip_local_traffic_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
On impacted versions and platforms the Trusted Platform Module (TPM) system integrity check cannot detect modifications to specific system components. This issue only impacts specific engineering hot…
|
NVD-CWE-Other
|
CVE-2020-5851
|
2024-11-21 14:34 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196765
|
7.5 |
HIGH
Network
|
pysaml2_project canonical debian
|
pysaml2 ubuntu_linux debian_linux
|
PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature in…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-5390
|
2024-11-21 14:34 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196766
|
8.8 |
HIGH
Network
|
phpmyadmin suse debian
|
phpmyadmin suse_linux_enterprise_server debian_linux
|
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this …
|
CWE-89
SQL Injection
|
CVE-2020-5504
|
2024-11-21 14:34 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196767
|
8.8 |
HIGH
Network
|
small_crm_project
|
small_crm
|
PHPGurukul Small CRM v2.0 was found vulnerable to authentication bypass via SQL injection when logging into the administrator login page.
|
CWE-89
SQL Injection
|
CVE-2020-5511
|
2024-11-21 14:34 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196768
|
9.8 |
CRITICAL
Network
|
phpgurukul
|
hostel_management_system
|
PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file.
|
CWE-89
SQL Injection
|
CVE-2020-5510
|
2024-11-21 14:34 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196769
|
9.8 |
CRITICAL
Network
|
opservices
|
opmon
|
An issue was discovered in OpServices OpMon 9.3.1-1. Using password change parameters, an attacker could perform SQL injection without authentication.
|
CWE-89
SQL Injection
|
CVE-2020-5841
|
2024-11-21 14:34 |
2020-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196770
|
6.1 |
MEDIUM
Network
|
codologic
|
codoforum
|
Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI. The payload is, for example, executed on the admin/index.php?page=users/manage …
|
CWE-79
Cross-site Scripting
|
CVE-2020-5842
|
2024-11-21 14:34 |
2020-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|