|
210731
|
9.3 |
CRITICAL
Network
|
sylabs opensuse
|
singularity leap backports_sle
|
Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of path traversal and the lack of path sanitization within `unsquashfs`,…
|
-
|
CVE-2020-15229
|
2024-11-21 14:05 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210732
|
6.8 |
MEDIUM
Adjacent
|
openenclave
|
openenclave
|
In Open Enclave before version 0.12.0, an information disclosure vulnerability exists when an enclave application using the syscalls provided by the sockets.edl is loaded by a malicious host applicat…
|
NVD-CWE-Other
|
CVE-2020-15224
|
2024-11-21 14:05 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210733
|
6.5 |
MEDIUM
Network
|
mirahezebots
|
channelmgnt
|
In the Channelmgnt plug-in for Sopel (a Python IRC bot) before version 1.0.3, malicious users are able to op/voice and take over a channel. This is an ACL bypass vulnerability. This plugin is bundled…
|
CWE-862
Missing Authorization
|
CVE-2020-15251
|
2024-11-21 14:05 |
2020-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210734
|
5.5 |
MEDIUM
Local
|
junit debian apache oracle
|
junit4 debian_linux pluto communications_cloud_native_core_policy
|
In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like systems, the system's temporary directory is shared bet…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-15250
|
2024-11-21 14:05 |
2020-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210735
|
9.8 |
CRITICAL
Network
|
smartstore
|
smartstore
|
Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plu…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-15243
|
2024-11-21 14:05 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210736
|
6.1 |
MEDIUM
Network
|
typo3
|
fluid_engine typo3
|
TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vulnerable to cross-site scripting when making use of the ternary conditional oper…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15241
|
2024-11-21 14:05 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210737
|
6.1 |
MEDIUM
Network
|
vercel
|
next.js
|
Next.js versions >=9.5.0 and <9.5.4 are vulnerable to an Open Redirect. Specially encoded paths could be used with the trailing slash redirect to allow an open redirect to occur to an external site. …
|
-
|
CVE-2020-15242
|
2024-11-21 14:05 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210738
|
5.9 |
MEDIUM
Network
|
mozilla
|
thunderbird
|
If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunde…
|
NVD-CWE-noinfo
|
CVE-2020-15646
|
2024-11-21 14:05 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210739
|
6.5 |
MEDIUM
Network
|
smarter
|
smarter_coffee_maker_1st_generation
|
Smarter Coffee Maker before 2nd generation allows firmware replacement without authentication or authorization. User interaction is required to press a button. NOTE: This vulnerability only affects p…
|
NVD-CWE-noinfo
|
CVE-2020-15501
|
2024-11-21 14:05 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210740
|
5.3 |
MEDIUM
Network
|
glpi-project
|
glpi
|
In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in version 9.5.0 and patched in 9.5.2. As a workaround, disable public access to …
|
-
|
CVE-2020-15217
|
2024-11-21 14:05 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|