|
196891
|
8.8 |
HIGH
Network
|
plone
|
plone
|
SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)
|
CWE-89
SQL Injection
|
CVE-2020-7939
|
2024-11-21 14:38 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196892
|
8.8 |
HIGH
Network
|
plone
|
plone
|
plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.
|
NVD-CWE-noinfo
|
CVE-2020-7938
|
2024-11-21 14:38 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196893
|
5.4 |
MEDIUM
Network
|
plone
|
plone
|
An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a certain privilege level to insert JavaScript that will be executed when other users access the site.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7937
|
2024-11-21 14:38 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196894
|
6.1 |
MEDIUM
Network
|
plone
|
plone
|
An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redire…
|
CWE-601
Open Redirect
|
CVE-2020-7936
|
2024-11-21 14:38 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196895
|
8.8 |
HIGH
Network
|
jfrog
|
artifactory
|
In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modifying a .ssh/authorized_keys file. Patches are available for various versions be…
|
NVD-CWE-noinfo
|
CVE-2020-7931
|
2024-11-21 14:38 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196896
|
4.8 |
MEDIUM
Network
|
eaton
|
5p_850_firmware
|
An issue was discovered on Eaton 5P 850 devices. The Ubicacion SAI field allows XSS attacks by an administrator.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7915
|
2024-11-21 14:38 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196897
|
9.8 |
CRITICAL
Network
|
get-npm-package-version_project
|
get-npm-package-version
|
The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js.
|
CWE-77
Command Injection
|
CVE-2020-7795
|
2024-11-21 14:37 |
2022-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196898
|
9.8 |
CRITICAL
Network
|
node-import_project
|
node-import
|
This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located …
|
NVD-CWE-noinfo
|
CVE-2020-7678
|
2024-11-21 14:37 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196899
|
9.8 |
CRITICAL
Network
|
thenify_project debian fedoraproject
|
thenify debian_linux fedora
|
This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any san…
|
NVD-CWE-noinfo
|
CVE-2020-7677
|
2024-11-21 14:37 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196900
|
4.9 |
MEDIUM
Network
|
snyk
|
broker
|
This affects the package snyk-broker before 4.73.0. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.
|
CWE-22
Path Traversal
|
CVE-2020-7649
|
2024-11-21 14:37 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|