|
211021
|
9.1 |
CRITICAL
Network
|
broadcom fedoraproject
|
tcpreplay fedora
|
tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-12740
|
2024-11-21 14:00 |
2020-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211022
|
6.5 |
MEDIUM
Network
|
maxum
|
rumpus
|
An issue was discovered in Maxum Rumpus before 8.2.12 on macOS. Authenticated users can perform a path traversal using double escaped characters, enabling read access to arbitrary files on the server.
|
CWE-22
Path Traversal
|
CVE-2020-12737
|
2024-11-21 14:00 |
2020-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211023
|
5.5 |
MEDIUM
Local
|
avira
|
free_antivirus
|
Avira Free Antivirus through 15.0.2005.1866 allows local users to discover user credentials. The functions of the executable file Avira.PWM.NativeMessaging.exe are aimed at collecting credentials sto…
|
NVD-CWE-noinfo
|
CVE-2020-12680
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211024
|
9.8 |
CRITICAL
Network
|
domainmod
|
domainmod
|
reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.
|
CWE-331
Insufficient Entropy
|
CVE-2020-12735
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211025
|
9.8 |
CRITICAL
Network
|
vbulletin
|
vbulletin
|
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.
|
CWE-89 CWE-306
SQL Injection Missing Authentication for Critical Function
|
CVE-2020-12720
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211026
|
7.2 |
HIGH
Network
|
wso2
|
identity_server_analytics identity_server identity_server_as_key_manager enterprise_integrator api_microgateway api_manager_analytics api_manager
|
XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, API Microgateway 2.2.0, Enterprise Integrator 6.4.0…
|
CWE-611
XXE
|
CVE-2020-12719
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211027
|
5.4 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comment feature. The protection mechanism can be bypass…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12718
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211028
|
6.1 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to downloads/downloads.php or article.php. N…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12708
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211029
|
6.1 |
MEDIUM
Network
|
lepton-cms
|
lepton_cms
|
An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elements. A malicious a…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12707
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211030
|
5.4 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12706
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|