|
197111
|
6.5 |
MEDIUM
Network
|
github_flavored_markdown_project fedoraproject
|
github_flavored_markdown fedora
|
The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long…
|
-
|
CVE-2020-5238
|
2024-11-21 14:33 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197112
|
5.4 |
MEDIUM
Network
|
dell
|
powermax_os emc_unisphere_for_powermax_virtual_appliance emc_unisphere_for_powermax
|
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an authorization bypass …
|
CWE-862
Missing Authorization
|
CVE-2020-5345
|
2024-11-21 14:33 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197113
|
7.8 |
HIGH
Local
|
dell
|
endpoint_security_suite_enterprise encryption
|
Dell Encryption versions prior to 10.7 and Dell Endpoint Security Suite versions prior to 2.7 contain a privilege escalation vulnerability due to incorrect permissions. A local malicious user with lo…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-5358
|
2024-11-21 14:33 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197114
|
4.4 |
MEDIUM
Local
|
dell
|
chengming_3967_firmware chengming_3977_firmware chengming_3980_firmware chengming_3988_firmware chengming_3990_firmware chengming_3991_firmware g3_15_3500_firmware g3_15_3590_fir…
|
Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS adm…
|
CWE-862
Missing Authorization
|
CVE-2020-5362
|
2024-11-21 14:33 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197115
|
7.5 |
HIGH
Network
|
whitesourcesoftware
|
whitesource
|
The dashboard in WhiteSource Application Vulnerability Management (AVM) before version 20.4.1 allows Log Injection via a %0A%0D substring in the idp parameter to the /saml/login URI. This closes the …
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2020-5304
|
2024-11-21 14:33 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197116
|
4.8 |
MEDIUM
Network
|
octobercms
|
october
|
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, a user with the ability to use the import functionality of the `ImportExportController` behavior can be soci…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5298
|
2024-11-21 14:33 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197117
|
5.1 |
MEDIUM
Network
|
octobercms
|
october
|
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, any users with the ability to modify any data that could eventually be exported as a CSV file from the `Impo…
|
CWE-77
Command Injection
|
CVE-2020-5299
|
2024-11-21 14:33 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197118
|
2.7 |
LOW
Network
|
octobercms
|
october
|
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to upload jpg, jpeg, bmp, png, webp, gif, ico, css, js, woff, wof…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2020-5297
|
2024-11-21 14:33 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197119
|
4.9 |
MEDIUM
Network
|
octobercms
|
october
|
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to delete arbitrary local files of an October CMS server. The vul…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2020-5296
|
2024-11-21 14:33 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197120
|
4.9 |
MEDIUM
Network
|
octobercms
|
october
|
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to read local files of an October CMS server. The vulnerability i…
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2020-5295
|
2024-11-21 14:33 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|