|
212691
|
9.1 |
CRITICAL
Network
|
styria
|
django-rest-framework-json_web_tokens
|
An issue was discovered in drf-jwt 1.15.x before 1.15.1. It allows attackers with access to a notionally invalidated token to obtain a new, working token via the refresh endpoint, because the blackli…
|
CWE-287
Improper Authentication
|
CVE-2020-10594
|
2024-11-21 13:55 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212692
|
7.5 |
HIGH
Network
|
walmart
|
concord
|
An issue was discovered in Walmart Labs Concord before 1.44.0. CORS Access-Control-Allow-Origin headers have a potentially unsafe dependency on Origin headers, and are not configurable. This allows r…
|
NVD-CWE-noinfo
|
CVE-2020-10591
|
2024-11-21 13:55 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212693
|
7.8 |
HIGH
Local
|
v2rayl_project
|
v2rayl
|
v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/config.json is owned by a low-privileged user but contains commands that are executed as root, after v2rayL.service is resta…
|
CWE-269
Improper Privilege Management
|
CVE-2020-10589
|
2024-11-21 13:55 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212694
|
7.8 |
HIGH
Local
|
v2rayl_project
|
v2rayl
|
v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/add.sh and /etc/v2rayL/remove.sh are owned by a low-privileged user but execute as root via Sudo.
|
CWE-269
Improper Privilege Management
|
CVE-2020-10588
|
2024-11-21 13:55 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212695
|
7.8 |
HIGH
Local
|
antixlinux mxlinux
|
antix_linux mx_linux
|
antiX and MX Linux allow local users to achieve root access via "persist-config --command /bin/sh" because of the Sudo configuration.
|
NVD-CWE-noinfo
|
CVE-2020-10587
|
2024-11-21 13:55 |
2020-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212696
|
7.5 |
HIGH
Network
|
q-cms
|
qcms
|
An arbitrary file read vulnerability exists in system/controller/backend/template.php in QCMS v3.0.1.
|
NVD-CWE-noinfo
|
CVE-2020-10578
|
2024-11-21 13:55 |
2020-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212697
|
4.8 |
MEDIUM
Network
|
meetecho
|
janus
|
An issue was discovered in Janus through 0.9.1. janus.c has multiple concurrent threads that misuse the source property of a session, leading to a race condition when claiming sessions.
|
CWE-362
Race Condition
|
CVE-2020-10577
|
2024-11-21 13:55 |
2020-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212698
|
5.9 |
MEDIUM
Network
|
meetecho
|
janus
|
An issue was discovered in Janus through 0.9.1. plugins/janus_voicemail.c in the VoiceMail plugin has a race condition that could cause a server crash.
|
CWE-362
Race Condition
|
CVE-2020-10576
|
2024-11-21 13:55 |
2020-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212699
|
4.2 |
MEDIUM
Network
|
meetecho
|
janus
|
An issue was discovered in Janus through 0.9.1. plugins/janus_videocall.c in the VideoCall plugin mishandles session management because a race condition causes some references to be freed too early o…
|
CWE-362
Race Condition
|
CVE-2020-10575
|
2024-11-21 13:55 |
2020-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212700
|
9.8 |
CRITICAL
Network
|
meetecho
|
janus
|
An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "query_logger" Admin API request, because of a typo in the JSON validation.
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2020-10574
|
2024-11-21 13:55 |
2020-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|