|
209921
|
5.9 |
MEDIUM
Network
|
djangoproject canonical fedoraproject netapp debian oracle
|
django ubuntu_linux fedora steelstore_cloud_integrated_storage sra_plugin debian_linux zfs_storage_appliance_kit
|
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collis…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-13254
|
2024-11-21 14:00 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209922
|
8.0 |
HIGH
Network
|
synacor
|
zimbra_collaboration_suite
|
Zimbra before 8.8.15 Patch 10 and 9.x before 9.0.0 Patch 3 allows remote code execution via an avatar file. There is potential abuse of /service/upload servlet in the webmail subsystem. A user can up…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-12846
|
2024-11-21 14:00 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209923
|
8.8 |
HIGH
Network
|
sysax
|
multi_server
|
An issue was discovered in Sysax Multi Server 6.90. A session can be hijacked if one observes the sid value in any /scgi URI, because it is an authentication token.
|
CWE-384
Session Fixation
|
CVE-2020-13229
|
2024-11-21 14:00 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209924
|
6.1 |
MEDIUM
Network
|
sysax
|
multi_server
|
An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13228
|
2024-11-21 14:00 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209925
|
5.3 |
MEDIUM
Network
|
sysax
|
multi_server
|
An issue was discovered in Sysax Multi Server 6.90. An attacker can determine the username (under which the web server is running) by triggering an invalid path permission error. This bypasses the fa…
|
CWE-22
Path Traversal
|
CVE-2020-13227
|
2024-11-21 14:00 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209926
|
5.5 |
MEDIUM
Local
|
sane-project fedoraproject debian opensuse canonical
|
sane_backends fedora debian_linux leap ubuntu_linux
|
A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-20…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-12867
|
2024-11-21 14:00 |
2020-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209927
|
8.8 |
HIGH
Network
|
mappresspro
|
mappress
|
The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related to creation/retrieval/deletion of PHP template file…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-12675
|
2024-11-21 14:00 |
2020-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209928
|
7.8 |
HIGH
Local
|
teradici
|
pcoip_graphics_agent pcoip_standard_agent
|
Initialization of the pcoip_credential_provider in Teradici PCoIP Standard Agent for Windows and PCoIP Graphics Agent for Windows versions 19.11.1 and earlier creates an insecure named pipe, which al…
|
CWE-362
Race Condition
|
CVE-2020-13173
|
2024-11-21 14:00 |
2020-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209929
|
5.9 |
MEDIUM
Network
|
netgear
|
r6120_firmware r6220_firmware r6350_firmware r6400_firmware r6800_firmware r6850_firmware r7000p_firmware r7800_firmware r8000_firmware r9000_firmware rax120_firmware
|
Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10, and possibly R6120, R7800, R6220, R8000, R6350, R9000, R6400,…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-13245
|
2024-11-21 14:00 |
2020-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209930
|
5.5 |
MEDIUM
Local
|
qemu canonical debian
|
qemu ubuntu_linux debian_linux
|
sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS user can crash the QEMU process.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-13253
|
2024-11-21 14:00 |
2020-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|