|
211971
|
6.1 |
MEDIUM
Network
|
tiny
|
tinymce
|
TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
|
CWE-79
Cross-site Scripting
|
CVE-2020-17480
|
2024-11-21 14:08 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211972
|
9.8 |
CRITICAL
Network
|
json_pattern_validator_project
|
json_pattern_validator
|
jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array.
|
CWE-20
Improper Input Validation
|
CVE-2020-17479
|
2024-11-21 14:08 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211973
|
7.5 |
HIGH
Network
|
p5-crypt-perl_project
|
p5-crypt-perl
|
ECDSA/EC/Point.pm in Crypt::Perl before 0.33 does not properly consider timing attacks against the EC point multiplication algorithm.
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-17478
|
2024-11-21 14:08 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211974
|
6.1 |
MEDIUM
Network
|
mibew
|
messenger
|
Mibew Messenger before 3.2.7 allows XSS via a crafted user name.
|
CWE-79
Cross-site Scripting
|
CVE-2020-17476
|
2024-11-21 14:08 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211975
|
7.2 |
HIGH
Network
|
flatcore
|
flatcore
|
flatCore before 1.5.7 allows upload and execution of a .php file by an admin.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-17452
|
2024-11-21 14:08 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211976
|
4.8 |
MEDIUM
Network
|
flatcore
|
flatcore
|
flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title, page_content, or page_extracontent parameter, or the acp/acp.php?tn=system&sub…
|
CWE-79
Cross-site Scripting
|
CVE-2020-17451
|
2024-11-21 14:08 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211977
|
7.8 |
HIGH
Local
|
microsoft
|
python_extension
|
Visual Studio Code Python Extension Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2020-17163
|
2024-11-21 14:07 |
2023-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211978
|
8.6 |
HIGH
Local
|
lilypond
|
lilypond
|
LilyPond before 2.24 allows attackers to bypass the -dsafe protection mechanism via output-def-lookup or output-def-scope, as demonstrated by dangerous Scheme code in a .ly file that causes arbitrary…
|
CWE-863
Incorrect Authorization
|
CVE-2020-17354
|
2024-11-21 14:07 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211979
|
6.7 |
MEDIUM
Local
|
bbraun
|
datamodule_compactplus spacecom
|
A vulnerability in the configuration import mechanism of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with com…
|
-
|
CVE-2020-16238
|
2024-11-21 14:07 |
2022-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211980
|
9.8 |
CRITICAL
Network
|
telosalliance
|
z\/ip_one_firmware
|
A directory traversal vulnerability on Telos Z/IP One devices through 4.0.0r grants an unauthenticated individual root level access to the device's file system. This can be used to identify configura…
|
CWE-22
Path Traversal
|
CVE-2020-17383
|
2024-11-21 14:07 |
2022-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|