|
209341
|
7.5 |
HIGH
Network
|
mind
|
imind_server
|
InterMind iMind Server through 3.13.65 allows remote unauthenticated attackers to read the self-diagnostic archive via a direct api/rs/monitoring/rs/api/system/dump-diagnostic-info?server=127.0.0.1 r…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2020-24765
|
2024-11-21 14:16 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209342
|
7.8 |
HIGH
Local
|
socket.io-file_project
|
socket.io-file
|
The socket.io-file package through 2.0.31 for Node.js relies on client-side validation of file types, which allows remote attackers to execute arbitrary code by uploading an executable file via a mod…
|
CWE-20
Improper Input Validation
|
CVE-2020-24807
|
2024-11-21 14:16 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209343
|
7.5 |
HIGH
Network
|
envoyproxy
|
envoy
|
Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization.
|
NVD-CWE-noinfo
|
CVE-2020-25018
|
2024-11-21 14:16 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209344
|
8.3 |
HIGH
Network
|
envoyproxy
|
envoy
|
Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy’s setCopy() header map API does not replace all existing occurences of a non-i…
|
NVD-CWE-Other
|
CVE-2020-25017
|
2024-11-21 14:16 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209345
|
5.4 |
MEDIUM
Network
|
get-simple
|
getsimple_cms
|
GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page
|
CWE-79
Cross-site Scripting
|
CVE-2020-24861
|
2024-11-21 14:16 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209346
|
5.4 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every …
|
CWE-79
Cross-site Scripting
|
CVE-2020-24860
|
2024-11-21 14:16 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209347
|
8.1 |
HIGH
Network
|
fasterxml oracle debian
|
jackson-databind application_testing_suite agile_plm communications_policy_management communications_diameter_signaling_router communications_offline_mediation_controller communicat…
|
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-24750
|
2024-11-21 14:16 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209348
|
9.8 |
CRITICAL
Network
|
objective_open_cbor_run-time_project
|
objective_open_cbor_run-time
|
A memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow an attacker to execute code via crafted Concise Binary Object Representation (CB…
|
CWE-787 CWE-755 CWE-908
Out-of-bounds Write Improper Handling of Exceptional Conditions Use of Uninitialized Resource
|
CVE-2020-24753
|
2024-11-21 14:16 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209349
|
8.8 |
HIGH
Network
|
sylabs opensuse
|
singularity leap
|
Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020-25039.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-25040
|
2024-11-21 14:16 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209350
|
8.1 |
HIGH
Network
|
sylabs opensuse
|
singularity leap
|
Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-25039
|
2024-11-21 14:16 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|