|
198451
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values.
|
CWE-200
Information Exposure
|
CVE-2020-35611
|
2024-11-21 14:27 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198452
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the access level of the corresponding terms.
|
NVD-CWE-noinfo
|
CVE-2020-35610
|
2024-11-21 14:27 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198453
|
8.8 |
HIGH
Network
|
woocommerce
|
gift_cards
|
Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary code. Once it contains the function "Custom Gift C…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-35627
|
2024-11-21 14:27 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198454
|
6.1 |
MEDIUM
Local
|
wavpack debian fedoraproject
|
wavpack debian_linux fedora
|
WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" re…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2020-35738
|
2024-11-21 14:27 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198455
|
7.5 |
HIGH
Network
|
liftoffsoftware
|
gateone
|
GateOne 1.1 allows arbitrary file download without authentication via /downloads/.. directory traversal because os.path.join is misused.
|
CWE-22
Path Traversal
|
CVE-2020-35736
|
2024-11-21 14:27 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198456
|
9.8 |
CRITICAL
Network
|
klogserver
|
klog_server
|
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
|
CWE-78
OS Command
|
CVE-2020-35729
|
2024-11-21 14:27 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198457
|
3.3 |
LOW
Local
|
gnu netapp
|
binutils ontap_select_deploy_administration_utility
|
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c beca…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-35448
|
2024-11-21 14:27 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198458
|
8.1 |
HIGH
Network
|
fasterxml debian netapp oracle
|
jackson-databind debian_linux service_level_manager webcenter_portal application_testing_suite primavera_unifier agile_plm communications_policy_management communications_bill…
|
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka e…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-35728
|
2024-11-21 14:27 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198459
|
6.1 |
MEDIUM
Network
|
crossbar
|
autobahn
|
Autobahn|Python before 20.12.3 allows redirect header injection.
|
CWE-601
Open Redirect
|
CVE-2020-35678
|
2024-11-21 14:27 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198460
|
9.8 |
CRITICAL
Network
|
flamingo_project
|
flamingo
|
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addUser.
|
CWE-89
SQL Injection
|
CVE-2020-35245
|
2024-11-21 14:27 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|