|
210841
|
5.4 |
MEDIUM
Network
|
mono
|
monox
|
MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12472
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210842
|
6.7 |
MEDIUM
Local
|
linux netapp
|
linux_kernel cloud_backup steelstore_cloud_integrated_storage hci_storage_nodes aff_a700s active_iq_unified_manager hci_compute_node solidfire_\&_hci_storage_node solidfir…
|
usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925.
|
CWE-416
Use After Free
|
CVE-2020-12464
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210843
|
6.7 |
MEDIUM
Local
|
linux netapp
|
linux_kernel cloud_backup steelstore_cloud_integrated_storage solidfire_\&_hci_management_node active_iq_unified_manager hci_compute_node solidfire_baseboard_management_controll…
|
An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10, aka CID-b102f0c522cf. An oversized packet with too many rx fragmen…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-12465
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210844
|
6.1 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms
|
The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.
|
CWE-352
Origin Validation Error
|
CVE-2020-12462
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210845
|
8.8 |
HIGH
Network
|
php-fusion
|
php-fusion
|
PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that can be inserted into the sort_order GET parameter…
|
CWE-89
SQL Injection
|
CVE-2020-12461
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210846
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-12277
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210847
|
4.8 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab 9.5.9 through 12.9 is vulnerable to stored XSS in an admin notification feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12276
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210848
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab 12.6 through 12.9 is vulnerable to a privilege escalation that allows an external user to create a personal snippet through the API.
|
NVD-CWE-noinfo
|
CVE-2020-12275
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210849
|
5.5 |
MEDIUM
Local
|
grafana fedoraproject
|
grafana fedora
|
In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world reada…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-12459
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210850
|
5.5 |
MEDIUM
Local
|
grafana redhat fedoraproject
|
grafana ceph_storage enterprise_linux fedora
|
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposur…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-12458
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|