|
197171
|
9.8 |
CRITICAL
Network
|
ispconfig
|
ispconfig
|
ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2020-9398
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197172
|
8.8 |
HIGH
Network
|
supsystic
|
pricing_table_by_supsystic
|
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-9394
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197173
|
6.1 |
MEDIUM
Network
|
supsystic
|
pricing_table_by_supsystic
|
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-9393
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197174
|
6.5 |
MEDIUM
Network
|
mitel
|
micontact_center_business
|
The Software Development Kit of the MiContact Center Business with Site Based Security 8.0 through 9.0.1.0 before KB496276 allows an authenticated user to access sensitive information. A successful e…
|
NVD-CWE-noinfo
|
CVE-2020-9379
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197175
|
5.5 |
MEDIUM
Local
|
linux fedoraproject netapp
|
linux_kernel fedora cloud_backup steelstore_cloud_integrated_storage data_availability_services solidfire hci_management_node active_iq_unified_manager h410c_firmware
|
An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-9391
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197176
|
4.8 |
MEDIUM
Network
|
10web
|
photo_gallery
|
Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploitation of this vulnerability would allow a authenticated admin user to inject arb…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9335
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197177
|
5.4 |
MEDIUM
Network
|
enviragallery
|
envira_gallery
|
A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitation of this vulnerability would allow a authenticated low-privileged user to inje…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9334
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197178
|
7.1 |
HIGH
Local
|
linux debian opensuse canonical netapp
|
linux_kernel debian_linux leap ubuntu_linux cloud_backup steelstore_cloud_integrated_storage data_availability_services solidfire hci_management_node active_iq_unified_mana…
|
An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before a…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-9383
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197179
|
7.5 |
HIGH
Network
|
zint
|
zint
|
A NULL Pointer Dereference exists in libzint in Zint 2.7.1 because multiple + characters are mishandled in add_on in upcean.c, when called from eanx in upcean.c during EAN barcode generation.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-9385
|
2024-11-21 14:40 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197180
|
5.4 |
MEDIUM
Network
|
widgets_project
|
widgets
|
An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page as a widget (as defined by this extension) via Med…
|
CWE-74
Injection
|
CVE-2020-9382
|
2024-11-21 14:40 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|