|
198321
|
7.5 |
HIGH
Network
|
mediawiki
|
mediawiki
|
An issue was discovered in the CasAuth extension for MediaWiki through 1.35.1. Due to improper username validation, it allowed user impersonation with trivial manipulations of certain characters with…
|
CWE-20 CWE-706
Improper Input Validation Use of Incorrectly-Resolved Name or Reference
|
CVE-2020-35623
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198322
|
6.1 |
MEDIUM
Network
|
mediawiki
|
mediawiki
|
An issue was discovered in the GlobalUsage extension for MediaWiki through 1.35.1. SpecialGlobalUsage.php calls WikiMap::makeForeignLink unsafely. The $page variable within the formatItem function wa…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35622
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198323
|
8.8 |
HIGH
Network
|
webmin
|
webmin
|
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C…
|
CWE-78
OS Command
|
CVE-2020-35606
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198324
|
9.8 |
CRITICAL
Network
|
kitty_project debian
|
kitty debian_linux
|
The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error messa…
|
NVD-CWE-Other
|
CVE-2020-35605
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198325
|
9.8 |
CRITICAL
Network
|
kronos
|
web_time_and_attendance
|
An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used.
|
CWE-611
XXE
|
CVE-2020-35604
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198326
|
6.5 |
MEDIUM
Network
|
ovirt redhat
|
ovirt-engine virtualization
|
A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email and public SSH key.
|
-
|
CVE-2020-35497
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198327
|
9.8 |
CRITICAL
Network
|
egavilanmedia
|
ecm_address_book
|
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
|
CWE-89
SQL Injection
|
CVE-2020-35276
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198328
|
5.4 |
MEDIUM
Network
|
coastercms
|
coastercms
|
Coastercms v5.8.18 is affected by cross-site Scripting (XSS). A user can steal a cookie and make the user redirect to any malicious website because it is trigged on the main home page of the product/…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35275
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198329
|
4.8 |
MEDIUM
Network
|
dotcms
|
dotcms
|
DotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges. An attacker could compromise the security of a website or web application through a sto…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35274
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198330
|
8.0 |
HIGH
Network
|
egavilanmedia
|
user_registration_\&_login_system_with_admin_panel
|
EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel. An attacker can update any …
|
CWE-352
Origin Validation Error
|
CVE-2020-35273
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|