|
210151
|
5.4 |
MEDIUM
Network
|
katyshop2_project
|
katyshop2
|
Katyshop2 before 2.12 has multiple stored XSS issues.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12683
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210152
|
6.1 |
MEDIUM
Network
|
iframe_project
|
iframe
|
The iframe plugin before 4.5 for WordPress does not sanitize a URL.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12696
|
2024-11-21 14:00 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210153
|
5.4 |
MEDIUM
Network
|
openstack canonical
|
keystone ubuntu_linux
|
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then …
|
CWE-347 CWE-294
Improper Verification of Cryptographic Signature Authentication Bypass by Capture-replay
|
CVE-2020-12692
|
2024-11-21 14:00 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210154
|
8.8 |
HIGH
Network
|
openstack canonical
|
keystone ubuntu_linux
|
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a project that they have a specified role on, and then …
|
CWE-863
Incorrect Authorization
|
CVE-2020-12691
|
2024-11-21 14:00 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210155
|
8.8 |
HIGH
Network
|
openstack
|
keystone
|
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is used to request a key…
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-12690
|
2024-11-21 14:00 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210156
|
8.8 |
HIGH
Network
|
openstack canonical
|
keystone ubuntu_linux
|
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application credential) can create an EC2 credential with an escala…
|
CWE-269
Improper Privilege Management
|
CVE-2020-12689
|
2024-11-21 14:00 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210157
|
8.8 |
HIGH
Network
|
dolibarr
|
dolibarr
|
core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric menu parameter.
|
CWE-20
Improper Input Validation
|
CVE-2020-12669
|
2024-11-21 14:00 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210158
|
7.5 |
HIGH
Network
|
graphicsmagick debian opensuse
|
graphicsmagick debian_linux leap backports_sle
|
GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12672
|
2024-11-21 14:00 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210159
|
6.1 |
MEDIUM
Network
|
go-macaron fedoraproject
|
macaron fedora
|
macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.com/ URL.
|
CWE-601
Open Redirect
|
CVE-2020-12666
|
2024-11-21 14:00 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210160
|
6.7 |
MEDIUM
Local
|
linux netapp
|
linux_kernel cloud_backup steelstore_cloud_integrated_storage solidfire_\&_hci_management_node active_iq_unified_manager solidfire_baseboard_management_controller hci_baseboard_…
|
An issue was discovered in the Linux kernel before 5.6.7. xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write (by a user with the CAP_NET_ADMIN capability) because of a lack of headroom val…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12659
|
2024-11-21 14:00 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|