|
210501
|
8.8 |
HIGH
Network
|
zulip
|
zulip_server
|
Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write a crafted custom profile field value.
|
CWE-94
Code Injection
|
CVE-2020-15070
|
2024-11-21 14:04 |
2020-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210502
|
8.0 |
HIGH
Network
|
openmage magento
|
openmage_long_term_support magento
|
OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks. …
|
CWE-352
Origin Validation Error
|
CVE-2020-15151
|
2024-11-21 14:04 |
2020-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210503
|
8.8 |
HIGH
Network
|
sylius
|
syliusresourcebundle
|
In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, request parameters injected inside an expression evaluated by `symfony/expression-language` package haven't been sanitized prop…
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2020-15146
|
2024-11-21 14:04 |
2020-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210504
|
8.8 |
HIGH
Network
|
sylius
|
syliusresourcebundle
|
In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, rrequest parameters injected inside an expression evaluated by `symfony/expression-language` package haven't been sanitized pro…
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2020-15143
|
2024-11-21 14:04 |
2020-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210505
|
5.4 |
MEDIUM
Network
|
auth0
|
lock
|
In auth0-lock versions before and including 11.25.1, dangerouslySetInnerHTML is used to update the DOM. When dangerouslySetInnerHTML is used, the application and its users might be exposed to cross-s…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15119
|
2024-11-21 14:04 |
2020-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210506
|
9.9 |
CRITICAL
Network
|
nodebb
|
nodebb
|
NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user on a running NodeBB forum by sending a specially …
|
CWE-287
Improper Authentication
|
CVE-2020-15149
|
2024-11-21 14:04 |
2020-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210507
|
9.1 |
CRITICAL
Network
|
contiki-ng
|
contiki-ng
|
Memory access out of buffer boundaries issues was discovered in Contiki-NG 4.4 through 4.5, in the SNMP BER encoder/decoder. The length of provided input/output buffers is insufficiently verified dur…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-14937
|
2024-11-21 14:04 |
2020-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210508
|
9.8 |
CRITICAL
Network
|
contiki-ng
|
contiki-ng
|
Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP agent. Functions parsing the OIDs in SNMP requests lack sufficient allocated target-buffer capacity verification when writi…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-14936
|
2024-11-21 14:04 |
2020-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210509
|
9.8 |
CRITICAL
Network
|
contiki-ng
|
contiki-ng
|
Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP bulk get request response encoding function. The function parsing the received SNMP request does not verify the input messa…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-14935
|
2024-11-21 14:04 |
2020-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210510
|
9.8 |
CRITICAL
Network
|
contiki-ng
|
contiki-ng
|
Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP agent. The function parsing the received SNMP request does not verify the input message's requested variables against the c…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-14934
|
2024-11-21 14:04 |
2020-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|