|
209781
|
6.1 |
MEDIUM
Network
|
online_hotel_booking_system_project
|
online_hotel_booking_system
|
An issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can occur via any of the registration fields.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15536
|
2024-11-21 14:05 |
2020-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209782
|
6.1 |
MEDIUM
Network
|
bestsoftinc
|
car_rental_system
|
An issue was discovered in the bestsoftinc Car Rental System plugin through 1.3 for WordPress. Persistent XSS can occur via any of the registration fields.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15535
|
2024-11-21 14:05 |
2020-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209783
|
7.5 |
HIGH
Network
|
wireshark opensuse debian
|
wireshark leap debian_linux
|
In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gvcp.c by ensuring that an offset increases in all situations.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-15466
|
2024-11-21 14:05 |
2020-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209784
|
7.8 |
HIGH
Local
|
valvesoftware
|
steam_client
|
An issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain NT AUTHORITY\SYSTEM privileges because some parts of %PROGRAMFILES(X86)%\Steam and/or %COMMONPROGRAM…
|
CWE-362
Race Condition
|
CVE-2020-15530
|
2024-11-21 14:05 |
2020-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209785
|
7.8 |
HIGH
Local
|
gog
|
galaxy
|
An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user installs a game or performs a verify/repair operation. The issue exists because of weak fil…
|
CWE-667 CWE-732
Improper Locking Incorrect Permission Assignment for Critical Resource
|
CVE-2020-15529
|
2024-11-21 14:05 |
2020-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209786
|
7.8 |
HIGH
Local
|
gog
|
galaxy
|
An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user starts or uninstalls a game because of weak file permissions and missing file integrity che…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-15528
|
2024-11-21 14:05 |
2020-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209787
|
7.8 |
HIGH
Local
|
python netapp
|
python snapcenter
|
In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native appl…
|
CWE-427 CWE-908
Uncontrolled Search Path Element Use of Uninitialized Resource
|
CVE-2020-15523
|
2024-11-21 14:05 |
2020-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209788
|
8.8 |
HIGH
Network
|
veeam
|
veeam_availability_suite veeam_backup_\&_replication
|
VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged users to achieve total control over filesystem I/O req…
|
CWE-862
Missing Authorization
|
CVE-2020-15518
|
2024-11-21 14:05 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209789
|
2.3 |
LOW
Local
|
qemu debian
|
qemu debian_linux
|
In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-15469
|
2024-11-21 14:05 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209790
|
7.5 |
HIGH
Network
|
libraw fedoraproject debian
|
libraw fedora debian_linux
|
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed…
|
CWE-20
Improper Input Validation
|
CVE-2020-15503
|
2024-11-21 14:05 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|