|
208311
|
7.8 |
HIGH
Local
|
xen opensuse debian fedoraproject
|
xen leap debian_linux fedora
|
An issue was discovered in Xen through 4.14.x allowing x86 HVM and PVH guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because coalescing…
|
NVD-CWE-noinfo
|
CVE-2020-27671
|
2024-11-21 14:21 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208312
|
7.8 |
HIGH
Local
|
xen opensuse fedoraproject debian
|
xen leap fedora debian_linux
|
An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because an AMD IOMMU page-tabl…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-27670
|
2024-11-21 14:21 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208313
|
5.4 |
MEDIUM
Network
|
strapi
|
strapi
|
Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-27666
|
2024-11-21 14:21 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208314
|
7.5 |
HIGH
Network
|
strapi
|
strapi
|
In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-27665
|
2024-11-21 14:21 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208315
|
9.8 |
CRITICAL
Network
|
strapi
|
strapi
|
admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.
|
NVD-CWE-noinfo
|
CVE-2020-27664
|
2024-11-21 14:21 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208316
|
5.4 |
MEDIUM
Network
|
dedecms
|
dedecms
|
A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web p…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27533
|
2024-11-21 14:21 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208317
|
6.5 |
MEDIUM
Network
|
biscom
|
secure_file_transfer
|
Biscom Secure File Transfer (SFT) before 5.1.1082 and 6.x before 6.0.1011 allows user credential theft.
|
NVD-CWE-noinfo
|
CVE-2020-27646
|
2024-11-21 14:21 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208318
|
3.3 |
LOW
Local
|
imagemagick debian opensuse
|
imagemagick debian_linux leap
|
ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCore/layer.c, which may cause a denial of service.
|
CWE-369
Divide By Zero
|
CVE-2020-27560
|
2024-11-21 14:21 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208319
|
6.1 |
MEDIUM
Network
|
bigbluebutton
|
greenlight
|
A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.
|
CWE-79
Cross-site Scripting
|
CVE-2020-27642
|
2024-11-21 14:21 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208320
|
7.5 |
HIGH
Network
|
fastd_project debian fedoraproject
|
fastd debian_linux fedora
|
receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.
|
CWE-617
Reachable Assertion
|
CVE-2020-27638
|
2024-11-21 14:21 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|