|
212631
|
7.8 |
HIGH
Local
|
amd
|
ryzen_master
|
A vulnerability in a dynamically loaded AMD driver in AMD Ryzen Master V15 may allow any authenticated user to escalate privileges to NT authority system.
|
NVD-CWE-noinfo
|
CVE-2020-12928
|
2024-11-21 14:00 |
2020-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212632
|
5.5 |
MEDIUM
Local
|
amd
|
atikmdag.sys
|
A denial of service vulnerability exists in the D3DKMTCreateAllocation handler functionality of AMD ATIKMDAG.SYS (e.g. version 26.20.15029.27017). A specially crafted D3DKMTCreateAllocation API reque…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-12911
|
2024-11-21 14:00 |
2020-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212633
|
6.1 |
MEDIUM
Network
|
webmin
|
webmin
|
XSS exists in Webmin 1.941 and earlier affecting the Save function of the Read User Email Module / mailboxes Endpoint when attempting to save HTML emails. This module parses any output without saniti…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12670
|
2024-11-21 14:00 |
2020-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212634
|
9.1 |
CRITICAL
Network
|
fusionauth
|
samlv2
|
FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack".
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-12676
|
2024-11-21 14:00 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212635
|
6.1 |
MEDIUM
Network
|
sysaid
|
sysaidsy_on-premises sysaid_on-premises
|
SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13168
|
2024-11-21 14:00 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212636
|
9.8 |
CRITICAL
Network
|
rainbowfishsoftware
|
pacsone_server
|
RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page.
|
CWE-89
SQL Injection
|
CVE-2020-12870
|
2024-11-21 14:00 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212637
|
5.4 |
MEDIUM
Network
|
rainbowfishsoftware
|
pacsone_server
|
RainbowFish PacsOne Server 6.8.4 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12869
|
2024-11-21 14:00 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212638
|
8.8 |
HIGH
Network
|
rainbowfishsoftware
|
pacsone_server
|
RainbowFish PacsOne Server 6.8.4 has Incorrect Access Control.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-12715
|
2024-11-21 14:00 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212639
|
8.8 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens
|
CWE-862
Missing Authorization
|
CVE-2020-13296
|
2024-11-21 14:00 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212640
|
7.5 |
HIGH
Network
|
pexip
|
pexip_infinity
|
Pexip Infinity 23.x before 23.3 has improper input validation, leading to a temporary software abort via RTP.
|
CWE-20
Improper Input Validation
|
CVE-2020-12824
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|