|
210971
|
7.2 |
HIGH
Network
|
devome
|
grr
|
An issue was discovered in DEVOME GRR before 3.4.1c. admin_edit_room.php mishandles file uploads.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-10562
|
2024-11-21 13:55 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210972
|
6.1 |
MEDIUM
Network
|
primetek
|
primefaces
|
An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, an attacker can provide JavaScript code in an input field whose data is later u…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10544
|
2024-11-21 13:55 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210973
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_opmanager
|
Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. This was fixed in 12.5.108.
|
NVD-CWE-noinfo
|
CVE-2020-10541
|
2024-11-21 13:55 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210974
|
8.8 |
HIGH
Network
|
untis
|
webuntis
|
Untis WebUntis before 2020.9.6 allows CSRF for certain combinations of rights and modules.
|
CWE-352
Origin Validation Error
|
CVE-2020-10540
|
2024-11-21 13:55 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210975
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.
|
NVD-CWE-noinfo
|
CVE-2020-10535
|
2024-11-21 13:55 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210976
|
9.8 |
CRITICAL
Network
|
mediawiki
|
mediawiki
|
In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges. This is related to t…
|
CWE-863
Incorrect Authorization
|
CVE-2020-10534
|
2024-11-21 13:55 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210977
|
7.5 |
HIGH
Network
|
watchguard
|
ad_helper_firmware
|
The AD Helper component in WatchGuard Fireware before 5.8.5.10317 allows remote attackers to discover cleartext passwords via the /domains/list URI.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-10532
|
2024-11-21 13:55 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210978
|
8.8 |
HIGH
Network
|
icu-project redhat google fedoraproject debian canonical opensuse oracle nodejs
|
international_components_for_unicode enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation chrome fedora debian_linux ubuntu_linux leap banking_exte…
|
An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() fun…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2020-10531
|
2024-11-21 13:55 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210979
|
4.3 |
MEDIUM
Network
|
chadhaajay
|
phpkb
|
CSRF in admin/edit-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a comment, given the id, via a crafted request.
|
CWE-352
Origin Validation Error
|
CVE-2020-10504
|
2024-11-21 13:55 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210980
|
4.3 |
MEDIUM
Network
|
chadhaajay
|
phpkb
|
CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to disapprove any comment, given the id, via a crafted request.
|
CWE-352
Origin Validation Error
|
CVE-2020-10503
|
2024-11-21 13:55 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|