|
210651
|
8.1 |
HIGH
Network
|
jupyterhub
|
kubespawner
|
In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant them access to the default server of other users who have matching usernames. T…
|
CWE-863
Incorrect Authorization
|
CVE-2020-15110
|
2024-11-21 14:04 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210652
|
7.1 |
HIGH
Network
|
glpi-project
|
glpi
|
In glpi before 9.5.1, there is a SQL injection for all usages of "Clone" feature. This has been fixed in 9.5.1.
|
CWE-89
SQL Injection
|
CVE-2020-15108
|
2024-11-21 14:04 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210653
|
5.9 |
MEDIUM
Network
|
gnome debian fedoraproject canonical
|
evolution-data-server debian_linux fedora ubuntu_linux
|
evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS c…
|
CWE-74
Injection
|
CVE-2020-14928
|
2024-11-21 14:04 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210654
|
9.8 |
CRITICAL
Network
|
connectwise
|
automate
|
ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7 and in a hotfix fo…
|
CWE-287
Improper Authentication
|
CVE-2020-15027
|
2024-11-21 14:04 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210655
|
6.1 |
MEDIUM
Network
|
articatech
|
artica_proxy
|
An issue was discovered in Artica Proxy before 4.30.000000. Stored XSS exists via the Server Domain Name, Your Email Address, Group Name, MYSQL Server, Database, MYSQL Username, Group Name, and Task …
|
CWE-79
Cross-site Scripting
|
CVE-2020-15051
|
2024-11-21 14:04 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210656
|
6.5 |
MEDIUM
Network
|
kronos
|
web_time_and_attendance
|
A Blind SQL Injection vulnerability in Kronos WebTA 3.8.x and later before 4.0 (affecting the com.threeis.webta.H352premPayRequest servlet's SortBy parameter) allows an attacker with the Employee, Su…
|
CWE-89
SQL Injection
|
CVE-2020-14982
|
2024-11-21 14:04 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210657
|
5.3 |
MEDIUM
Local
|
openenclave
|
openenclave
|
In openenclave before 0.10.0, enclaves that use x87 FPU operations are vulnerable to tampering by a malicious host application. By violating the Linux System V Application Binary Interface (ABI) for …
|
NVD-CWE-noinfo
|
CVE-2020-15107
|
2024-11-21 14:04 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210658
|
6.5 |
MEDIUM
Network
|
symless fedoraproject
|
synergy fedora
|
In Synergy before version 1.12.0, a Synergy server can be crashed by receiving a kMsgHelloBack packet with a client name length set to 0xffffffff (4294967295) if the servers memory is less than 4 GB.…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2020-15117
|
2024-11-21 14:04 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210659
|
3.3 |
LOW
Local
|
schokokeks
|
freewvs
|
In freewvs before 0.1.1, a directory structure of more than 1000 nested directories can interrupt a freewvs scan due to Python's recursion limit and os.walk(). This can be problematic in a case where…
|
CWE-674
Uncontrolled Recursion
|
CVE-2020-15101
|
2024-11-21 14:04 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210660
|
3.3 |
LOW
Local
|
schokokeks
|
freewvs
|
In freewvs before 0.1.1, a user could create a large file that freewvs will try to read, which will terminate a scan process. This has been patched in 0.1.1.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-15100
|
2024-11-21 14:04 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|