|
210101
|
4.3 |
MEDIUM
Network
|
dkd
|
direct_mail
|
The direct_mail extension through 5.2.3 for TYPO3 allows Information Disclosure via a newsletter subscriber data Special Query.
|
CWE-862
Missing Authorization
|
CVE-2020-12700
|
2024-11-21 14:00 |
2020-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210102
|
6.1 |
MEDIUM
Network
|
dkd
|
direct_mail
|
The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl.
|
CWE-601
Open Redirect
|
CVE-2020-12699
|
2024-11-21 14:00 |
2020-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210103
|
4.3 |
MEDIUM
Network
|
dkd
|
direct_mail
|
The direct_mail extension through 5.2.3 for TYPO3 has Broken Access Control for newsletter subscriber tables.
|
CWE-862
Missing Authorization
|
CVE-2020-12698
|
2024-11-21 14:00 |
2020-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210104
|
5.3 |
MEDIUM
Network
|
dkd
|
direct_mail
|
The direct_mail extension through 5.2.3 for TYPO3 allows Denial of Service via log entries.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-12697
|
2024-11-21 14:00 |
2020-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210105
|
8.8 |
HIGH
Network
|
igniterealtime
|
spark
|
An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC attribute referencing an external host's IP addres…
|
CWE-200
Information Exposure
|
CVE-2020-12772
|
2024-11-21 14:00 |
2020-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210106
|
5.3 |
MEDIUM
Local
|
linux redhat canonical
|
linux_kernel enterprise_linux ubuntu_linux enterprise_mrg
|
A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-12826
|
2024-11-21 14:00 |
2020-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210107
|
7.1 |
HIGH
Network
|
gnome
|
libcroco
|
libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption.
|
CWE-674
Uncontrolled Recursion
|
CVE-2020-12825
|
2024-11-21 14:00 |
2020-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210108
|
9.8 |
CRITICAL
Network
|
infradead fedoraproject debian opensuse
|
openconnect fedora debian_linux leap
|
OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to get_cert_name in gnutls.c.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-12823
|
2024-11-21 14:00 |
2020-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210109
|
7.5 |
HIGH
Network
|
nystudio107
|
seomatic
|
In the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does not properly sanitize the URL. This leads to Server-Side Template Injection and credentials disclosure via a crafted T…
|
CWE-74
Injection
|
CVE-2020-12790
|
2024-11-21 14:00 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210110
|
8.1 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 86.0.14 allows attackers to obtain access to the current working directory via the account backup feature (SEC-540).
|
NVD-CWE-noinfo
|
CVE-2020-12785
|
2024-11-21 14:00 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|