|
210801
|
5.4 |
MEDIUM
Network
|
typo3
|
svg_sanitizer
|
The SVG Sanitizer extension for TYPO3 has a cross-site scripting vulnerability in versions before 1.0.3. Slightly invalid or incomplete SVG markup is not correctly processed and thus not sanitized at…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11070
|
2024-11-21 13:56 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210802
|
2.2 |
LOW
Network
|
freerdp canonical debian
|
freerdp ubuntu_linux debian_linux
|
In FreeRDP after 1.1 and before 2.0.0, a stream out-of-bounds seek in rdp_read_font_capability_set could lead to a later out-of-bounds read. As a result, a manipulated client or server might force a …
|
-
|
CVE-2020-11058
|
2024-11-21 13:56 |
2020-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210803
|
8.8 |
HIGH
Network
|
xwiki
|
xwiki
|
In XWiki Platform 7.2 through 11.10.2, registered users without scripting/programming permissions are able to execute python/groovy scripts while editing personal dashboards. This has been fixed 11.3…
|
CWE-94
Code Injection
|
CVE-2020-11057
|
2024-11-21 13:56 |
2020-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210804
|
5.4 |
MEDIUM
Network
|
glpi-project
|
glpi
|
In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type. This has been fixed in version 9.4.6.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11062
|
2024-11-21 13:56 |
2020-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210805
|
8.8 |
HIGH
Network
|
glpi-project
|
glpi
|
In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited by an attacker without a valid account by using a…
|
CWE-352
Origin Validation Error
|
CVE-2020-11060
|
2024-11-21 13:56 |
2020-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210806
|
8.6 |
HIGH
Network
|
simpleledger
|
slp-validate
|
In SLP Validate (npm package slp-validate) before version 1.2.1, users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow…
|
CWE-697
Incorrect Comparison
|
CVE-2020-11072
|
2024-11-21 13:56 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210807
|
8.6 |
HIGH
Network
|
simpleledger
|
slpjs
|
SLPJS (npm package slpjs) before version 0.27.2, has a vulnerability where users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet c…
|
CWE-697
Incorrect Comparison
|
CVE-2020-11071
|
2024-11-21 13:56 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210808
|
8.8 |
HIGH
Network
|
pi-hole
|
pi-hole
|
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Al…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-11108
|
2024-11-21 13:56 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210809
|
5.4 |
MEDIUM
Network
|
shopizer
|
shopizer
|
In Shopizer before version 2.11.0, a script can be injected in various forms and saved in the database, then executed when information is fetched from backend. This has been patched in version 2.11.0.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11006
|
2024-11-21 13:56 |
2020-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210810
|
8.0 |
HIGH
Adjacent
|
tp-link
|
tl-wa855re_firmware
|
This vulnerability allows network-adjacent attackers to escalate privileges on affected installations of TP-Link TL-WA855RE Firmware Ver: 855rev4-up-ver1-0-1-P1[20191213-rel60361] Wi-Fi extenders. Al…
|
CWE-287
Improper Authentication
|
CVE-2020-10916
|
2024-11-21 13:56 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|