|
198681
|
7.8 |
HIGH
Local
|
microsoft
|
azure_sphere
|
A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted AF_PACKET socket can cause a process to create an …
|
CWE-74
Injection
|
CVE-2020-35608
|
2024-11-21 14:27 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198682
|
8.8 |
HIGH
Network
|
mediawiki
|
mediawiki
|
An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks agains…
|
CWE-352
Origin Validation Error
|
CVE-2020-35626
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198683
|
8.8 |
HIGH
Network
|
mediawiki
|
mediawiki
|
An issue was discovered in the Widgets extension for MediaWiki through 1.35.1. Any user with the ability to edit pages within the Widgets namespace could call any static function within any class (de…
|
CWE-862
Missing Authorization
|
CVE-2020-35625
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198684
|
5.3 |
MEDIUM
Network
|
mediawiki
|
mediawiki
|
An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may provide unintended clues about how a voting process…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-35624
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198685
|
7.5 |
HIGH
Network
|
mediawiki
|
mediawiki
|
An issue was discovered in the CasAuth extension for MediaWiki through 1.35.1. Due to improper username validation, it allowed user impersonation with trivial manipulations of certain characters with…
|
CWE-20 CWE-706
Improper Input Validation Use of Incorrectly-Resolved Name or Reference
|
CVE-2020-35623
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198686
|
6.1 |
MEDIUM
Network
|
mediawiki
|
mediawiki
|
An issue was discovered in the GlobalUsage extension for MediaWiki through 1.35.1. SpecialGlobalUsage.php calls WikiMap::makeForeignLink unsafely. The $page variable within the formatItem function wa…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35622
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198687
|
8.8 |
HIGH
Network
|
webmin
|
webmin
|
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C…
|
CWE-78
OS Command
|
CVE-2020-35606
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198688
|
9.8 |
CRITICAL
Network
|
kitty_project debian
|
kitty debian_linux
|
The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error messa…
|
NVD-CWE-Other
|
CVE-2020-35605
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198689
|
9.8 |
CRITICAL
Network
|
kronos
|
web_time_and_attendance
|
An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used.
|
CWE-611
XXE
|
CVE-2020-35604
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198690
|
6.5 |
MEDIUM
Network
|
ovirt redhat
|
ovirt-engine virtualization
|
A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email and public SSH key.
|
-
|
CVE-2020-35497
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|