|
208791
|
7.5 |
HIGH
Network
|
hashicorp
|
consul
|
HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes. Fixed in 1.7.9 and 1.8.5.
|
NVD-CWE-noinfo
|
CVE-2020-25201
|
2024-11-21 14:17 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208792
|
2.6 |
LOW
Network
|
cyberark
|
privileged_session_manager
|
CyberArk Privileged Session Manager (PSM) 10.9.0.15 allows attackers to discover internal pathnames by reading an error popup message after two hours of idle time.
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-25374
|
2024-11-21 14:17 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208793
|
5.5 |
MEDIUM
Local
|
innogames
|
god_kings
|
The God Kings application 0.60.1 for Android exposes a broadcast receiver to other apps called com.innogames.core.frontend.notifications.receivers.LocalNotificationBroadcastReceiver. The purpose of t…
|
NVD-CWE-Other
|
CVE-2020-25204
|
2024-11-21 14:17 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208794
|
7.5 |
HIGH
Network
|
we-con
|
levistudiou
|
An XXE vulnerability exists within LeviStudioU Release Build 2019-09-21 and prior when processing parameter entities, which may allow file disclosure.
|
CWE-611
XXE
|
CVE-2020-25186
|
2024-11-21 14:17 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208795
|
7.5 |
HIGH
Network
|
advantech
|
r-seenet
|
The R-SeeNet webpage (1.5.1 through 2.4.10) suffers from SQL injection, which allows a remote attacker to invoke queries on the database and retrieve sensitive information.
|
CWE-89
SQL Injection
|
CVE-2020-25157
|
2024-11-21 14:17 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208796
|
8.1 |
HIGH
Network
|
overwolf
|
overwolf
|
In the client in Overwolf 0.149.2.30, a channel can be accessed or influenced by an actor that is not an endpoint.
|
NVD-CWE-Other
|
CVE-2020-25214
|
2024-11-21 14:17 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208797
|
7.8 |
HIGH
Local
|
laquisscada
|
scada
|
An attacker who convinces a valid user to open a specially crafted project file to exploit could execute code under the privileges of the application due to an out-of-bounds read vulnerability on the…
|
-
|
CVE-2020-25188
|
2024-11-21 14:17 |
2020-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208798
|
9.8 |
CRITICAL
Network
|
online_bus_booking_system_project
|
online_bus_booking_system
|
In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.
|
CWE-89
SQL Injection
|
CVE-2020-25273
|
2024-11-21 14:17 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208799
|
6.1 |
MEDIUM
Network
|
online_bus_booking_system_project
|
online_bus_booking_system
|
In SourceCodester Online Bus Booking System 1.0, there is XSS through the name parameter in book_now.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25272
|
2024-11-21 14:17 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208800
|
5.4 |
MEDIUM
Network
|
phpgurukul
|
hospital_management_system
|
PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25271
|
2024-11-21 14:17 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|