|
210861
|
7.7 |
HIGH
Network
|
tiny_file_manager_project
|
tiny_file_manager
|
In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionality. This allows authenticated users to enumerate directories and files on the fi…
|
CWE-22
Path Traversal
|
CVE-2020-12102
|
2024-11-21 13:59 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210862
|
6.5 |
MEDIUM
Network
|
redhat
|
libvirt enterprise_linux
|
An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is respons…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-12430
|
2024-11-21 13:59 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210863
|
9.8 |
CRITICAL
Network
|
phpgurukul
|
online_course_registration
|
Online Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and authentication bypass in the login pages: admin/change-password.php, admin/check_a…
|
CWE-89
SQL Injection
|
CVE-2020-12429
|
2024-11-21 13:59 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210864
|
7.5 |
HIGH
Network
|
openldap debian opensuse canonical netapp broadcom apple oracle
|
openldap debian_linux leap ubuntu_linux cloud_backup steelstore_cloud_integrated_storage h410c_firmware h300s_firmware h500s_firmware h700s_firmware h300e_firmware h5…
|
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
|
CWE-674
Uncontrolled Recursion
|
CVE-2020-12243
|
2024-11-21 13:59 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210865
|
4.3 |
MEDIUM
Network
|
octopus
|
octopus_deploy
|
In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension. For example, a scoped user who is scoped to only one tenant can view server tasks…
|
NVD-CWE-noinfo
|
CVE-2020-12286
|
2024-11-21 13:59 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210866
|
9.8 |
CRITICAL
Network
|
ffmpeg canonical debian
|
ffmpeg ubuntu_linux debian_linux
|
cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MARKER_SOS handling because of a missing length check.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12284
|
2024-11-21 13:59 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210867
|
8.8 |
HIGH
Network
|
opmantek
|
open-audit
|
An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/configuration/ URI. An attacker can exploit this by adding an excluded IP address t…
|
CWE-78
OS Command
|
CVE-2020-12078
|
2024-11-21 13:59 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210868
|
9.8 |
CRITICAL
Network
|
libgit2 debian
|
libgit2 debian_linux
|
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when c…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2020-12279
|
2024-11-21 13:59 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210869
|
9.8 |
CRITICAL
Network
|
libgit2 debian
|
libgit2 debian_linux
|
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2020-12278
|
2024-11-21 13:59 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210870
|
7.5 |
HIGH
Network
|
wavlink
|
wl-wn579g3_firmware wl-wn575a3_firmware wl-wn530hg4_firmware wn531g3_firmware wn533a8_firmware wn531a6_firmware wn551k1_firmware wn535g3_firmware wn530h4_firmware wn57x93_f…
|
An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage. The devices automatically…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-12266
|
2024-11-21 13:59 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|