|
209341
|
7.7 |
HIGH
Network
|
tgstation13
|
tgstation-server
|
In tgstation-server 4.4.0 and 4.4.1, an authenticated user with permission to download logs can download any file on the server machine (accessible by the owner of the server process) via directory t…
|
CWE-22
Path Traversal
|
CVE-2020-16136
|
2024-11-21 14:06 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209342
|
9.8 |
CRITICAL
Network
|
springblade_project
|
springblade
|
The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.
|
CWE-89
SQL Injection
|
CVE-2020-16165
|
2024-11-21 14:06 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209343
|
7.4 |
HIGH
Network
|
ripe
|
rpki_validator_3
|
An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent rou…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-16164
|
2024-11-21 14:06 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209344
|
9.1 |
CRITICAL
Network
|
ripe
|
rpki_validator_3
|
An issue was discovered in RIPE NCC RPKI Validator 3.x before 3.1-2020.07.06.14.28. RRDP fetches proceed even with a lack of validation of a TLS HTTPS endpoint. This allows remote attackers to bypass…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-16163
|
2024-11-21 14:06 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209345
|
7.5 |
HIGH
Network
|
ripe
|
rpki_validator_3
|
An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. Missing validation checks on CRL presence or CRL staleness in the X509-based RPKI certificate-tree validation proc…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-16162
|
2024-11-21 14:06 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209346
|
5.4 |
MEDIUM
Network
|
nagios
|
log_server
|
A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu.
|
CWE-79
Cross-site Scripting
|
CVE-2020-16157
|
2024-11-21 14:06 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209347
|
3.7 |
LOW
Network
|
linux opensuse fedoraproject debian canonical netapp oracle
|
linux_kernel leap fedora debian_linux ubuntu_linux steelstore_cloud_integrated_storage active_iq_unified_manager solidfire hci_management_node cloud_volumes_ontap_mediator<…
|
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is relat…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-16166
|
2024-11-21 14:06 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209348
|
7.5 |
HIGH
Network
|
dp3t-backend-software_development_kit_project
|
dp3t-backend-software_development_kit
|
An issue was discovered in DP3T-Backend-SDK before 1.1.1 for Decentralised Privacy-Preserving Proximity Tracing (DP3T). When it is configured to check JWT before uploading/publishing keys, it is poss…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-15957
|
2024-11-21 14:06 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209349
|
7.8 |
HIGH
Local
|
seafile
|
seafile-client
|
The seafile-client client 7.0.8 for Seafile is vulnerable to DLL hijacking because it loads exchndl.dll from the current working directory.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-16143
|
2024-11-21 14:06 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209350
|
5.9 |
MEDIUM
Network
|
libssh debian fedoraproject canonical oracle
|
libssh debian_linux fedora ubuntu_linux communications_cloud_native_core_policy
|
libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-16135
|
2024-11-21 14:06 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|