|
208651
|
7.5 |
HIGH
Network
|
moodle fedoraproject
|
moodle fedora
|
In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.…
|
CWE-863
Incorrect Authorization
|
CVE-2020-25699
|
2024-11-21 14:18 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208652
|
7.5 |
HIGH
Network
|
moodle fedoraproject
|
moodle fedora
|
Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do …
|
NVD-CWE-noinfo
|
CVE-2020-25698
|
2024-11-21 14:18 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208653
|
6.1 |
MEDIUM
Network
|
kyocera
|
ecosys_m2640idw_firmware
|
The web application of Kyocera printer (ECOSYS M2640IDW) is affected by Stored XSS vulnerability, discovered in the addition a new contact in "Machine Address Book". Successful exploitation of this v…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25890
|
2024-11-21 14:18 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208654
|
5.4 |
MEDIUM
Network
|
limesurvey
|
limesurvey
|
A stored cross-site scripting (XSS) vulnerability in LimeSurvey before and including 3.21.1 allows authenticated users with correct permissions to inject arbitrary web script or HTML via parameter Pa…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25798
|
2024-11-21 14:18 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208655
|
4.6 |
MEDIUM
Physics
|
resourcexpress
|
qubi3_firmware
|
QED ResourceXpress Qubi3 devices before 1.40.9 could allow a local attacker (with physical access to the device) to obtain sensitive information via the debug interface (keystrokes over a USB cable),…
|
CWE-200
Information Exposure
|
CVE-2020-25746
|
2024-11-21 14:18 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208656
|
4.8 |
MEDIUM
Network
|
microfocus
|
idol
|
Persistent cross-Site Scripting vulnerability on Micro Focus IDOL product, affecting all version prior to version 12.7. The vulnerability could be exploited to perform Persistent XSS attack.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25833
|
2024-11-21 14:18 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208657
|
5.4 |
MEDIUM
Network
|
microfocus
|
filr
|
Reflected Cross Site scripting vulnerability on Micro Focus Filr product, affecting version 4.2.1. The vulnerability could be exploited to perform Reflected XSS attack.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25832
|
2024-11-21 14:18 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208658
|
7.4 |
HIGH
Network
|
linux redhat
|
linux_kernel enterprise_linux
|
A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Soft…
|
-
|
CVE-2020-25705
|
2024-11-21 14:18 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208659
|
5.4 |
MEDIUM
Network
|
microfocus
|
arcsight_logger
|
Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting version 7.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS).
|
CWE-79
Cross-site Scripting
|
CVE-2020-25834
|
2024-11-21 14:18 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208660
|
8.8 |
HIGH
Network
|
postgresql debian
|
postgresql debian_linux
|
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at leas…
|
-
|
CVE-2020-25695
|
2024-11-21 14:18 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|