|
198251
|
6.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability.
|
CWE-352
Origin Validation Error
|
CVE-2020-35615
|
2024-11-21 14:27 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198252
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration attack vector in the backend login page.
|
NVD-CWE-noinfo
|
CVE-2020-35614
|
2024-11-21 14:27 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198253
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backend user list.
|
CWE-89
SQL Injection
|
CVE-2020-35613
|
2024-11-21 14:27 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198254
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability.
|
CWE-22
Path Traversal
|
CVE-2020-35612
|
2024-11-21 14:27 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198255
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values.
|
CWE-200
Information Exposure
|
CVE-2020-35611
|
2024-11-21 14:27 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198256
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the access level of the corresponding terms.
|
NVD-CWE-noinfo
|
CVE-2020-35610
|
2024-11-21 14:27 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198257
|
8.8 |
HIGH
Network
|
woocommerce
|
gift_cards
|
Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary code. Once it contains the function "Custom Gift C…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-35627
|
2024-11-21 14:27 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198258
|
6.1 |
MEDIUM
Local
|
wavpack debian fedoraproject
|
wavpack debian_linux fedora
|
WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" re…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2020-35738
|
2024-11-21 14:27 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198259
|
7.5 |
HIGH
Network
|
liftoffsoftware
|
gateone
|
GateOne 1.1 allows arbitrary file download without authentication via /downloads/.. directory traversal because os.path.join is misused.
|
CWE-22
Path Traversal
|
CVE-2020-35736
|
2024-11-21 14:27 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198260
|
9.8 |
CRITICAL
Network
|
klogserver
|
klog_server
|
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
|
CWE-78
OS Command
|
CVE-2020-35729
|
2024-11-21 14:27 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|