|
209681
|
5.4 |
MEDIUM
Network
|
get-simple
|
getsimple_cms
|
GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page
|
CWE-79
Cross-site Scripting
|
CVE-2020-24861
|
2024-11-21 14:16 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209682
|
5.4 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every …
|
CWE-79
Cross-site Scripting
|
CVE-2020-24860
|
2024-11-21 14:16 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209683
|
8.1 |
HIGH
Network
|
fasterxml oracle debian
|
jackson-databind application_testing_suite agile_plm communications_policy_management communications_diameter_signaling_router communications_offline_mediation_controller communicat…
|
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-24750
|
2024-11-21 14:16 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209684
|
9.8 |
CRITICAL
Network
|
objective_open_cbor_run-time_project
|
objective_open_cbor_run-time
|
A memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow an attacker to execute code via crafted Concise Binary Object Representation (CB…
|
CWE-787 CWE-755 CWE-908
Out-of-bounds Write Improper Handling of Exceptional Conditions Use of Uninitialized Resource
|
CVE-2020-24753
|
2024-11-21 14:16 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209685
|
8.8 |
HIGH
Network
|
sylabs opensuse
|
singularity leap
|
Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020-25039.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-25040
|
2024-11-21 14:16 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209686
|
8.1 |
HIGH
Network
|
sylabs opensuse
|
singularity leap
|
Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-25039
|
2024-11-21 14:16 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209687
|
6.5 |
MEDIUM
Network
|
genexis
|
platinum_4410_firmware
|
A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices was found to be vulnerable to Broken Access Control …
|
CWE-352
Origin Validation Error
|
CVE-2020-25015
|
2024-11-21 14:16 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209688
|
5.5 |
MEDIUM
Local
|
libraw
|
libraw
|
libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs on…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-24890
|
2024-11-21 14:16 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209689
|
7.8 |
HIGH
Local
|
libraw
|
libraw
|
A buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedModel in src/metadata/normalize_model.cpp may lead to context-dependent arbitrary code execution.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-24889
|
2024-11-21 14:16 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209690
|
7.5 |
HIGH
Network
|
elkarbackup
|
elkarbackup
|
A Sensitive Source Code Path Disclosure vulnerability is found in ElkarBackup v1.3.3. An attacker is able to view the path of the source code jobs/sort where entire source code path is displayed in t…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-24925
|
2024-11-21 14:16 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|