|
209901
|
6.1 |
MEDIUM
Network
|
wordpress fedoraproject debian
|
wordpress fedora debian_linux
|
WordPress before 5.5.2 allows XSS associated with global variables.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28034
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209902
|
7.5 |
HIGH
Network
|
wordpress fedoraproject debian
|
wordpress fedora debian_linux
|
WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.
|
NVD-CWE-noinfo
|
CVE-2020-28033
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209903
|
9.8 |
CRITICAL
Network
|
wordpress fedoraproject debian
|
wordpress fedora debian_linux
|
WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-28032
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209904
|
4.3 |
MEDIUM
Network
|
eramba
|
eramba
|
eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenticated users.
|
CWE-20 CWE-74
Improper Input Validation Injection
|
CVE-2020-28031
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209905
|
7.5 |
HIGH
Network
|
wireshark debian fedoraproject
|
wireshark debian_linux fedora
|
In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.
|
CWE-682 CWE-770 CWE-835
Incorrect Calculation Allocation of Resources Without Limits or Throttling Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-28030
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209906
|
5.3 |
MEDIUM
Network
|
sonarsource
|
sonarqube
|
In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login option, anonymous authentication is forced. This allo…
|
CWE-287
Improper Authentication
|
CVE-2020-28002
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209907
|
7.8 |
HIGH
Local
|
wondershare
|
dr.fone
|
Dr.Fone 3.0.0 allows local users to gain privileges via a Trojan horse DriverInstall.exe because %PROGRAMFILES(X86)%\Wondershare\dr.fone\Library\DriverInstaller has Full Control for BUILTIN\Users.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-27992
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209908
|
6.1 |
MEDIUM
Network
|
icewarp
|
mail_server
|
IceWarp 11.4.5.0 allows XSS via the language parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-27982
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209909
|
9.8 |
CRITICAL
Network
|
fast-report
|
fastreport
|
An issue was discovered in FastReport before 2020.4.0. It lacks a ScriptSecurity feature and therefore may mishandle (for example) GetType, typeof, TypeOf, DllImport, LoadLibrary, and GetProcAddress.
|
CWE-862
Missing Authorization
|
CVE-2020-27998
|
2024-11-21 14:22 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209910
|
8.8 |
HIGH
Network
|
smartstore
|
smartstorenet
|
An issue was discovered in SmartStoreNET before 4.0.1. It does not properly consider the need for a CustomModelPartAttribute decoration in certain ModelBase.CustomProperties situations.
|
NVD-CWE-noinfo
|
CVE-2020-27996
|
2024-11-21 14:22 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|