|
198191
|
6.1 |
MEDIUM
Network
|
adminer
|
adminer
|
Adminer through 4.7.8 allows XSS via the history parameter to the default URI.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35572
|
2024-11-21 14:27 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198192
|
8.8 |
HIGH
Network
|
librenms
|
librenms
|
A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNMS before 21.1.0 allows remote authenticated attackers to execute arbitrary SQL …
|
CWE-89
SQL Injection
|
CVE-2020-35700
|
2024-11-21 14:27 |
2021-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198193
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-35667
|
2024-11-21 14:27 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198194
|
5.4 |
MEDIUM
Network
|
solarwinds
|
serv-u
|
SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35482
|
2024-11-21 14:27 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198195
|
9.8 |
CRITICAL
Network
|
solarwinds
|
serv-u
|
SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.
|
NVD-CWE-Other
|
CVE-2020-35481
|
2024-11-21 14:27 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198196
|
6.5 |
MEDIUM
Network
|
digium
|
asterisk
|
An issue was discovered in res_pjsip_diversion.c in Sangoma Asterisk before 13.38.0, 14.x through 16.x before 16.15.0, 17.x before 17.9.0, and 18.x before 18.1.0. A crash can occur when a SIP message…
|
NVD-CWE-noinfo
|
CVE-2020-35652
|
2024-11-21 14:27 |
2021-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198197
|
9.1 |
CRITICAL
Network
|
mitel
|
micollab
|
A library index page in NuPoint Messenger in Mitel MiCollab before 9.2 FP1 could allow an unauthenticated attacker to gain access (view and modify) to user data.
|
NVD-CWE-noinfo
|
CVE-2020-35547
|
2024-11-21 14:27 |
2021-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198198
|
8.2 |
HIGH
Local
|
qemu
|
qemu
|
A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared di…
|
-
|
CVE-2020-35517
|
2024-11-21 14:27 |
2021-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198199
|
8.8 |
HIGH
Network
|
tp-link
|
tl-wr841n_firmware
|
A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users to execute arbitrary code as root via shell metacha…
|
CWE-78
OS Command
|
CVE-2020-35576
|
2024-11-21 14:27 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198200
|
4.9 |
MEDIUM
Network
|
linux redhat
|
linux_kernel enterprise_linux
|
A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if b…
|
-
|
CVE-2020-35513
|
2024-11-21 14:27 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|