|
208681
|
6.5 |
MEDIUM
Network
|
python canonical debian oracle
|
urllib3 ubuntu_linux debian_linux zfs_storage_appliance_kit communications_cloud_native_core_network_function_cloud_native_environment
|
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: th…
|
CWE-74
Injection
|
CVE-2020-26137
|
2024-11-21 14:19 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208682
|
6.1 |
MEDIUM
Network
|
hoosk
|
hoosk
|
An issue was discovered in Hoosk CMS v1.8.0. There is a XSS vulnerability in install/index.php
|
CWE-79
Cross-site Scripting
|
CVE-2020-26043
|
2024-11-21 14:19 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208683
|
9.8 |
CRITICAL
Network
|
hoosk
|
hoosk
|
An issue was discovered in Hoosk CMS v1.8.0. There is a SQL injection vulnerability in install/index.php
|
CWE-89
SQL Injection
|
CVE-2020-26042
|
2024-11-21 14:19 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208684
|
9.8 |
CRITICAL
Network
|
hoosk
|
hoosk
|
An issue was discovered in Hoosk CmS v1.8.0. There is an Remote Code Execution vulnerability in install/index.php
|
NVD-CWE-noinfo
|
CVE-2020-26041
|
2024-11-21 14:19 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208685
|
7.5 |
HIGH
Network
|
mediawiki fedoraproject
|
mediawiki fedora
|
An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even when the target page is protected against "page creation" and the attacker should…
|
CWE-863
Incorrect Authorization
|
CVE-2020-26121
|
2024-11-21 14:19 |
2020-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208686
|
6.1 |
MEDIUM
Network
|
mediawiki fedoraproject
|
mediawiki fedora
|
XSS exists in the MobileFrontend extension for MediaWiki before 1.34.4 because section.line is mishandled during regex section line replacement from PageGateway. Using crafted HTML, an attacker can e…
|
CWE-79
Cross-site Scripting
|
CVE-2020-26120
|
2024-11-21 14:19 |
2020-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208687
|
8.1 |
HIGH
Network
|
tigervnc debian opensuse
|
tigervnc debian_linux leap
|
In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a cert…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-26117
|
2024-11-21 14:19 |
2020-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208688
|
7.2 |
HIGH
Network
|
python fedoraproject canonical netapp debian oracle opensuse
|
python fedora ubuntu_linux solidfire hci_storage_node debian_linux zfs_storage_appliance_kit leap
|
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by ins…
|
CWE-74
Injection
|
CVE-2020-26116
|
2024-11-21 14:19 |
2020-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208689
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 90.0.10 allows self XSS via the Cron Editor interface (SEC-574).
|
CWE-79
Cross-site Scripting
|
CVE-2020-26115
|
2024-11-21 14:19 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208690
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 90.0.10 allows self XSS via the Cron Jobs interface (SEC-573).
|
CWE-79
Cross-site Scripting
|
CVE-2020-26114
|
2024-11-21 14:19 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|