|
210221
|
8.8 |
HIGH
Network
|
tortoise_orm_project
|
tortoise_orm
|
In Tortoise ORM before versions 0.15.23 and 0.16.6, various forms of SQL injection have been found for MySQL and when filtering or doing mass-updates on char/text fields. SQLite & PostgreSQL are only…
|
CWE-89
SQL Injection
|
CVE-2020-11010
|
2024-11-21 13:56 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210222
|
5.4 |
MEDIUM
Network
|
zulip
|
zulip_server
|
Zulip Server before 2.1.3 allows XSS via a Markdown link, with resultant account takeover.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10935
|
2024-11-21 13:56 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210223
|
8.8 |
HIGH
Network
|
sophos
|
anti-virus_for_sophos_central anti-virus_for_sophos_home
|
Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation.
|
CWE-59
Link Following
|
CVE-2020-10947
|
2024-11-21 13:56 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210224
|
7.5 |
HIGH
Network
|
ftpdmin_project
|
ftpdmin
|
A buffer overflow vulnerability in FTPDMIN 0.96 allows attackers to crash the server via a crafted packet.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-10813
|
2024-11-21 13:56 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210225
|
6.5 |
MEDIUM
Network
|
shopizer
|
shopizer
|
In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated hence creating incorrect shopping cart and order total. This vulnerability make…
|
CWE-20
Improper Input Validation
|
CVE-2020-11007
|
2024-11-21 13:56 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210226
|
4.7 |
MEDIUM
Network
|
westerndigital
|
ibi my_cloud_home
|
Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages.
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-10951
|
2024-11-21 13:56 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210227
|
8.1 |
HIGH
Network
|
fraction
|
oasis
|
Oasis before version 2.15.0 has a potential DNS rebinding or CSRF vulnerability. If you're running a vulnerable application on your computer and an attacker can trick you into visiting a malicious we…
|
CWE-352
Origin Validation Error
|
CVE-2020-11003
|
2024-11-21 13:56 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210228
|
4.7 |
MEDIUM
Local
|
arm fedoraproject debian
|
mbed_tls fedora debian_linux
|
An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get precise enough side-channel measurements can recover the long-term ECDSA private key by (1) rec…
|
CWE-327 CWE-203
Use of a Broken or Risky Cryptographic Algorithm Information Exposure Through Discrepancy
|
CVE-2020-10932
|
2024-11-21 13:56 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210229
|
5.5 |
MEDIUM
Local
|
windowshello_project
|
windowshello
|
The WindowsHello open source library (NuGet HaemmerElectronics.SeppPenner.WindowsHello), before version 1.0.4, has a vulnerability where encrypted data could potentially be decrypted without needing …
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-11005
|
2024-11-21 13:56 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210230
|
6.8 |
MEDIUM
Network
|
torchbox
|
wagtail
|
In Wagtail before versions 2.8.1 and 2.7.2, a cross-site scripting (XSS) vulnerability exists on the page revision
comparison view within the Wagtail admin interface. A user with a limited-permission…
|
-
|
CVE-2020-11001
|
2024-11-21 13:56 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|