|
211101
|
5.5 |
MEDIUM
Local
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.9, an out-of-bounds read vulnerability exists within the ReadHEICImageByID function in coders\heic.c. It can be triggered via an image with a width or height value that exceeds the…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-10251
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211102
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because …
|
CWE-94 CWE-862
Code Injection Missing Authorization
|
CVE-2020-10257
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211103
|
9.8 |
CRITICAL
Network
|
meinbwa
|
direx-pro_firmware
|
BWA DiREX-Pro 1.2181 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the PKG parameter to uninstall.php3.
|
CWE-78
OS Command
|
CVE-2020-10250
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211104
|
5.3 |
MEDIUM
Network
|
meinbwa
|
direx-pro_firmware
|
BWA DiREX-Pro 1.2181 devices allow full path disclosure via an invalid name array parameter to val_soft.php3.
|
NVD-CWE-noinfo
|
CVE-2020-10249
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211105
|
7.5 |
HIGH
Network
|
meinbwa
|
direx-pro_firmware
|
BWA DiREX-Pro 1.2181 devices allow remote attackers to discover passwords via a direct request to val_users.php3.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2020-10248
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211106
|
6.1 |
MEDIUM
Network
|
misp
|
misp
|
MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is related to app/View/Elements/Events/View/sighting_field.ctp.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10247
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211107
|
6.1 |
MEDIUM
Network
|
misp
|
misp
|
MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is related to app/View/Users/statistics_orgs.ctp.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10246
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211108
|
7.5 |
HIGH
Network
|
jpaseto_project
|
jpaseto
|
JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-10244
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211109
|
5.5 |
MEDIUM
Local
|
froxlor
|
froxlor
|
An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords into files in /tmp, setting proper permissions only after writing the sensitive da…
|
CWE-362
Race Condition
|
CVE-2020-10237
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211110
|
6.1 |
MEDIUM
Local
|
froxlor
|
froxlor
|
An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the installation directory was not writable. This allowed local attackers to cause…
|
CWE-20
Improper Input Validation
|
CVE-2020-10236
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|