|
210031
|
7.5 |
HIGH
Network
|
advanced-woo-search
|
advanced_woo_search
|
The Advanced Woo Search plugin version through 1.99 for Wordpress suffers from a sensitive information disclosure vulnerability in every ajax search request via the sql field to includes/class-aws-se…
|
CWE-200
Information Exposure
|
CVE-2020-12070
|
2024-11-21 13:59 |
2020-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210032
|
6.1 |
MEDIUM
Network
|
grafana
|
grafana
|
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12245
|
2024-11-21 13:59 |
2020-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210033
|
6.1 |
MEDIUM
Network
|
gnu debian fedoraproject canonical opensuse
|
mailman debian_linux fedora ubuntu_linux leap backports_sle
|
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP repl…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12137
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210034
|
5.5 |
MEDIUM
Local
|
whoopsie_project mongodb
|
whoopsie c_driver
|
bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() parameter bytesNeeded could have an integer overflow …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-12135
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210035
|
9.8 |
CRITICAL
Network
|
nanometrics
|
titansma centaur
|
Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2020-12134
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210036
|
6.1 |
MEDIUM
Network
|
fifthplay
|
s.a.m.i
|
Fifthplay S.A.M.I before 2019.3_HP2 allows unauthenticated stored XSS via a POST request.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12132
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210037
|
6.1 |
MEDIUM
Network
|
app2pro
|
airdisk_pro
|
The AirDisk Pro app 5.5.3 for iOS allows XSS via the devicename parameter (shown next to the UI logo).
|
CWE-79
Cross-site Scripting
|
CVE-2020-12131
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210038
|
5.3 |
MEDIUM
Network
|
postfix
|
postfix
|
A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demonstrated by the similarity of \xce\xbf to the 'o' character…
|
NVD-CWE-Other
|
CVE-2020-12063
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210039
|
6.1 |
MEDIUM
Network
|
app2pro
|
airdisk_pro
|
The AirDisk Pro app 5.5.3 for iOS allows XSS via the deleteFile parameter of the Delete function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12130
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210040
|
6.1 |
MEDIUM
Network
|
app2pro
|
airdisk_pro
|
The AirDisk Pro app 5.5.3 for iOS allows XSS via the createFolder parameter of the Create Folder function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12129
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|