|
210071
|
9.8 |
CRITICAL
Network
|
springblade_project
|
springblade
|
The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.
|
CWE-89
SQL Injection
|
CVE-2020-16165
|
2024-11-21 14:06 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210072
|
7.4 |
HIGH
Network
|
ripe
|
rpki_validator_3
|
An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent rou…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-16164
|
2024-11-21 14:06 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210073
|
9.1 |
CRITICAL
Network
|
ripe
|
rpki_validator_3
|
An issue was discovered in RIPE NCC RPKI Validator 3.x before 3.1-2020.07.06.14.28. RRDP fetches proceed even with a lack of validation of a TLS HTTPS endpoint. This allows remote attackers to bypass…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-16163
|
2024-11-21 14:06 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210074
|
7.5 |
HIGH
Network
|
ripe
|
rpki_validator_3
|
An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. Missing validation checks on CRL presence or CRL staleness in the X509-based RPKI certificate-tree validation proc…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-16162
|
2024-11-21 14:06 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210075
|
5.4 |
MEDIUM
Network
|
nagios
|
log_server
|
A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu.
|
CWE-79
Cross-site Scripting
|
CVE-2020-16157
|
2024-11-21 14:06 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210076
|
3.7 |
LOW
Network
|
linux opensuse fedoraproject debian canonical netapp oracle
|
linux_kernel leap fedora debian_linux ubuntu_linux steelstore_cloud_integrated_storage active_iq_unified_manager solidfire hci_management_node cloud_volumes_ontap_mediator<…
|
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is relat…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-16166
|
2024-11-21 14:06 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210077
|
7.5 |
HIGH
Network
|
dp3t-backend-software_development_kit_project
|
dp3t-backend-software_development_kit
|
An issue was discovered in DP3T-Backend-SDK before 1.1.1 for Decentralised Privacy-Preserving Proximity Tracing (DP3T). When it is configured to check JWT before uploading/publishing keys, it is poss…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-15957
|
2024-11-21 14:06 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210078
|
7.8 |
HIGH
Local
|
seafile
|
seafile-client
|
The seafile-client client 7.0.8 for Seafile is vulnerable to DLL hijacking because it loads exchndl.dll from the current working directory.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-16143
|
2024-11-21 14:06 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210079
|
5.9 |
MEDIUM
Network
|
libssh debian fedoraproject canonical oracle
|
libssh debian_linux fedora ubuntu_linux communications_cloud_native_core_policy
|
libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-16135
|
2024-11-21 14:06 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210080
|
7.5 |
HIGH
Network
|
gnome opensuse
|
balsa leap backports_sle
|
In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/im…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-16118
|
2024-11-21 14:06 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|