|
210261
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration.
|
CWE-20
Improper Input Validation
|
CVE-2020-11890
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210262
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of usergroups.
|
NVD-CWE-noinfo
|
CVE-2020-11889
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210263
|
7.5 |
HIGH
Network
|
oppo
|
coloros
|
In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), RGB is defined on the stack but uninitialized, so when the s…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2020-11828
|
2024-11-21 13:58 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210264
|
7.8 |
HIGH
Local
|
re2c canonical
|
re2c ubuntu_linux
|
re2c 1.3 has a heap-based buffer overflow in Scanner::fill in parse/scanner.cc via a long lexeme.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-11958
|
2024-11-21 13:58 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210265
|
9.8 |
CRITICAL
Network
|
evenroute
|
iqrouter_firmware
|
IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter Injection. Note: The vendor claims that this vulnera…
|
CWE-78
OS Command
|
CVE-2020-11963
|
2024-11-21 13:58 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210266
|
6.1 |
MEDIUM
Network
|
bitcoin-abe_project
|
bitcoin-abe
|
Abe (aka bitcoin-abe) through 0.7.2, and 0.8pre, allows XSS in __call__ in abe.py because the PATH_INFO environment variable is mishandled during a PageNotFound exception.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11944
|
2024-11-21 13:58 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210267
|
7.5 |
HIGH
Network
|
zohocorp
|
manageengine_opmanager
|
Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-11946
|
2024-11-21 13:58 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210268
|
8.8 |
HIGH
Network
|
sonatype
|
nexus_repository_manager_3
|
An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks withou…
|
CWE-863
Incorrect Authorization
|
CVE-2020-11753
|
2024-11-21 13:58 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210269
|
6.1 |
MEDIUM
Network
|
python-markdown2_project
|
python-markdown2
|
python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11888
|
2024-11-21 13:58 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210270
|
6.1 |
MEDIUM
Network
|
gtranslate
|
translate_wordpress_with_gtranslate
|
The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11930
|
2024-11-21 13:58 |
2020-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|