|
197991
|
9.1 |
CRITICAL
Network
|
actix
|
actix-utils
|
An issue was discovered in the actix-utils crate before 2.0.0 for Rust. The Cell implementation allows obtaining more than one mutable reference to the same data.
|
CWE-416
Use After Free
|
CVE-2020-35898
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197992
|
9.8 |
CRITICAL
Network
|
hgiga
|
msr45_isherlock-user ssr45_isherlock-user
|
HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command inject attacks remotely and execute arbitrary commands of the system.
|
CWE-78
OS Command
|
CVE-2020-35851
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197993
|
7.5 |
HIGH
Network
|
mantisbt
|
mantisbt
|
An issue was discovered in MantisBT before 2.24.4. An incorrect access check in bug_revision_view_page.php allows an unprivileged attacker to view the Summary field of private issues, as well as bugn…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-35849
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197994
|
6.5 |
MEDIUM
Network
|
cockpit-project
|
cockpit
|
An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-35850
|
2024-11-21 14:28 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197995
|
9.8 |
CRITICAL
Network
|
agentejo
|
cockpit
|
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
|
CWE-89
SQL Injection
|
CVE-2020-35848
|
2024-11-21 14:28 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197996
|
9.8 |
CRITICAL
Network
|
agentejo
|
cockpit
|
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
|
CWE-89
SQL Injection
|
CVE-2020-35847
|
2024-11-21 14:28 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197997
|
9.8 |
CRITICAL
Network
|
agentejo
|
cockpit
|
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
|
CWE-89
SQL Injection
|
CVE-2020-35846
|
2024-11-21 14:28 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197998
|
5.4 |
MEDIUM
Network
|
netgear
|
d6200_firmware d7000_firmware jnr1010v2_firmware jr6150_firmware jwnr2010v5_firmware r6020_firmware r6050_firmware r6080_firmware r6120_firmware r6220_firmware r6260_fir…
|
Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v2 before 1.1.0.62, JR6150 before 1.0.1.24, JWNR2010v5 before 1.1.0.62, R6020 be…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35842
|
2024-11-21 14:28 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197999
|
7.6 |
HIGH
Network
|
netgear
|
d6200_firmware d7000_firmware jnr1010v2_firmware jr6150_firmware jwnr2010v5_firmware r6020_firmware r6050_firmware r6080_firmware r6120_firmware r6220_firmware r6260_fir…
|
Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v2 before 1.1.0.62, JR6150 before 1.0.1.24, JWNR2010v5 before 1.1.0.62, R6020 be…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35841
|
2024-11-21 14:28 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198000
|
5.4 |
MEDIUM
Network
|
netgear
|
d6200_firmware d7000_firmware jnr1010v2_firmware jr6150_firmware jwnr2010v5_firmware r6020_firmware r6050_firmware r6080_firmware r6120_firmware r6220_firmware r6260_fir…
|
Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v2 before 1.1.0.62, JR6150 before 1.0.1.24, JWNR2010v5 before 1.1.0.62, R6020 be…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35840
|
2024-11-21 14:28 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|