|
209891
|
5.9 |
MEDIUM
Network
|
getkirby
|
kirby panel
|
Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.3.6, and Kirby Panel before version 2.5.14 there is a vulnerability in which the admin panel may be accessed if hosted on a .dev domain. I…
|
CWE-346
Origin Validation Error
|
CVE-2020-26253
|
2024-11-21 14:19 |
2020-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209892
|
5.5 |
MEDIUM
Local
|
intland
|
codebeamer
|
An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM application to import projects, is parsed by insecurely configured software com…
|
CWE-611
XXE
|
CVE-2020-26513
|
2024-11-21 14:19 |
2020-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209893
|
7.2 |
HIGH
Network
|
inspur
|
nf8480m5_firmware nf8260m5_firmware ns5162m5_firmware ns5488m5_firmware ns5484m5_firmware ns5482m5_firmware nf5280m5_firmware nf5468m5_firmware nf5488m5-d_firmware nf5180m5…
|
Inspur NF5266M5 through 3.21.2 and other server M5 devices allow remote code execution via administrator privileges. The Baseboard Management Controller (BMC) program of INSPUR server is weak in chec…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-26122
|
2024-11-21 14:19 |
2020-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209894
|
8.2 |
HIGH
Network
|
prestashop
|
productcomments
|
In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module.
|
CWE-89
SQL Injection
|
CVE-2020-26248
|
2024-11-21 14:19 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209895
|
6.5 |
MEDIUM
Network
|
pimcore
|
pimcore
|
Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create website settings without having the appropriate permissions.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-26246
|
2024-11-21 14:19 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209896
|
6.8 |
MEDIUM
Network
|
python_openid_connect_project
|
python_openid_connect
|
Python oic is a Python OpenID Connect implementation. In Python oic before version 1.2.1, there are several related cryptographic issues affecting client implementations that use the library. The iss…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-26244
|
2024-11-21 14:19 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209897
|
6.3 |
MEDIUM
Network
|
jupyter
|
oauthenticator
|
OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the deprecated (in jupyterhub 1.2) configuration `Authenticator.whitelist`, which s…
|
CWE-863
Incorrect Authorization
|
CVE-2020-26250
|
2024-11-21 14:19 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209898
|
9.8 |
CRITICAL
Network
|
systeminformation
|
systeminformation
|
npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rewrite of shell sanitations to avoid prototyper poll…
|
CWE-78
OS Command
|
CVE-2020-26245
|
2024-11-21 14:19 |
2020-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209899
|
7.5 |
HIGH
Network
|
nanopb_project
|
nanopb
|
Nanopb is a small code-size Protocol Buffers implementation. In Nanopb before versions 0.4.4 and 0.3.9.7, decoding specifically formed message can leak memory if dynamic allocation is enabled and an …
|
-
|
CVE-2020-26243
|
2024-11-21 14:19 |
2020-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209900
|
6.5 |
MEDIUM
Network
|
glpi-project
|
glpi
|
GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. I…
|
-
|
CVE-2020-26212
|
2024-11-21 14:19 |
2020-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|