|
211301
|
6.3 |
MEDIUM
Network
|
octobercms
|
october
|
In OctoberCMS before version 1.0.468, encrypted cookie values were not tied to the name of the cookie the value belonged to. This meant that certain classes of attacks that took advantage of other th…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-15128
|
2024-11-21 14:04 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211302
|
7.5 |
HIGH
Network
|
simpleledger
|
slp-validate
|
In SLP Validate (npm package slp-validate) before version 1.2.2, there is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP w…
|
CWE-697
Incorrect Comparison
|
CVE-2020-15131
|
2024-11-21 14:04 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211303
|
7.5 |
HIGH
Network
|
simpleledger
|
slpjs
|
In SLPJS (npm package slpjs) before version 0.27.4, there is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or oppo…
|
CWE-697
Incorrect Comparison
|
CVE-2020-15130
|
2024-11-21 14:04 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211304
|
4.7 |
MEDIUM
Network
|
traefik
|
traefik
|
In Traefik before versions 1.7.26, 2.2.8, and 2.3.0-rc3, there exists a potential open redirect vulnerability in Traefik's handling of the "X-Forwarded-Prefix" header. The Traefik API dashboard compo…
|
CWE-601
Open Redirect
|
CVE-2020-15129
|
2024-11-21 14:04 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211305
|
7.7 |
HIGH
Network
|
auth0
|
auth0.js
|
In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Authorization header is …
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-15125
|
2024-11-21 14:04 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211306
|
8.1 |
HIGH
Network
|
typo3
|
typo3
|
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, in a case where an attacker manages to generate a valid cryptographic messa…
|
CWE-20
Improper Input Validation
|
CVE-2020-15099
|
2024-11-21 14:04 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211307
|
8.8 |
HIGH
Network
|
typo3
|
typo3
|
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered that an internal verification mechanism can be used …
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-15098
|
2024-11-21 14:04 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211308
|
9.8 |
CRITICAL
Network
|
typo3
|
mediace
|
In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification mechanism can be used to generate arbitrary check…
|
NVD-CWE-Other
|
CVE-2020-15086
|
2024-11-21 14:04 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211309
|
4.9 |
MEDIUM
Network
|
ihatemoney
|
i_hate_money
|
In "I hate money" before version 4.1.5, an authenticated member of one project can modify and delete members of another project, without knowledge of this other project's private code. This can be fu…
|
CWE-863
Incorrect Authorization
|
CVE-2020-15120
|
2024-11-21 14:04 |
2020-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211310
|
3.5 |
LOW
Network
|
freerdp fedoraproject opensuse canonical debian
|
freerdp fedora leap ubuntu_linux debian_linux
|
In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. All FreeRDP clients are affected. The input rectangles from the server are not c…
|
-
|
CVE-2020-15103
|
2024-11-21 14:04 |
2020-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|