|
198561
|
6.1 |
MEDIUM
Network
|
egavilanmedia
|
barcodes_generator
|
EGavilan Barcodes generator 1.0 is affected by: Cross Site Scripting (XSS) via the index.php. An Attacker is able to inject the XSS payload in the web application each time a user visits the website.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35396
|
2024-11-21 14:27 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198562
|
6.1 |
MEDIUM
Network
|
egavilanmedia
|
expense_management_system
|
XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code via the 'description' field
|
CWE-79
Cross-site Scripting
|
CVE-2020-35395
|
2024-11-21 14:27 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198563
|
7.5 |
HIGH
Network
|
envoyproxy
|
envoy
|
Envoy before 1.16.1 mishandles dropped and truncated datagrams, as demonstrated by a segmentation fault for a UDP packet size larger than 1500.
|
NVD-CWE-noinfo
|
CVE-2020-35471
|
2024-11-21 14:27 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198564
|
8.8 |
HIGH
Adjacent
|
envoyproxy
|
envoy
|
Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy protocol header. This affects situations with tcp-prox…
|
NVD-CWE-noinfo
|
CVE-2020-35470
|
2024-11-21 14:27 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198565
|
5.3 |
MEDIUM
Network
|
mpxj oracle
|
mpxj primavera_unifier
|
common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.
|
CWE-22
Path Traversal
|
CVE-2020-35460
|
2024-11-21 14:27 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198566
|
7.8 |
HIGH
Local
|
gnome
|
glib
|
GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entries. NOTE: the vendor's position is "Realistically this is not a security issue.…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2020-35457
|
2024-11-21 14:27 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198567
|
9.8 |
CRITICAL
Network
|
mobileviewpoint
|
wireless_multiplex_terminal_playout_server
|
The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier has a default account with a password of "pokon."
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-35338
|
2024-11-21 14:27 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198568
|
7.2 |
HIGH
Network
|
classroombookings
|
classroombookings
|
SQL Injection in Classbooking before 2.4.1 via the username field of a CSV file when adding a new user.
|
CWE-89
SQL Injection
|
CVE-2020-35382
|
2024-11-21 14:27 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198569
|
9.8 |
CRITICAL
Network
|
online_bus_ticket_reservation_project
|
online_bus_ticket_reservation
|
SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields.
|
CWE-89
SQL Injection
|
CVE-2020-35378
|
2024-11-21 14:27 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198570
|
5.3 |
MEDIUM
Network
|
amazee
|
lagoon
|
The GitLab Webhook Handler in amazee.io Lagoon before 1.12.3 has incorrect access control associated with project deletion.
|
NVD-CWE-noinfo
|
CVE-2020-35236
|
2024-11-21 14:27 |
2020-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|