|
208641
|
7.5 |
HIGH
Network
|
sized-chunks_project
|
sized-chunks
|
An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, the array size is not checked when constructed with unit().
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-25791
|
2024-11-21 14:18 |
2020-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208642
|
7.2 |
HIGH
Network
|
typesettercms
|
typesetter
|
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this report because "admins a…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-25790
|
2024-11-21 14:18 |
2020-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208643
|
6.1 |
MEDIUM
Network
|
tt-rss
|
tiny_tiny_rss
|
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25789
|
2024-11-21 14:18 |
2020-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208644
|
8.1 |
HIGH
Network
|
tt-rss
|
tiny_tiny_rss
|
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. imgproxy in plugins/af_proxy_http/init.php mishandles $_REQUEST["url"] in an error message.
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2020-25788
|
2024-11-21 14:18 |
2020-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208645
|
9.8 |
CRITICAL
Network
|
tt-rss
|
tiny_tiny_rss
|
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting them.
|
CWE-20
Improper Input Validation
|
CVE-2020-25787
|
2024-11-21 14:18 |
2020-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208646
|
6.1 |
MEDIUM
Network
|
dlink
|
dir-803_firmware dir-816l_firmware dir-645_firmware dir-815_firmware dir-860l_firmware dir-865l_firmware
|
webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25786
|
2024-11-21 14:18 |
2020-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208647
|
5.3 |
MEDIUM
Network
|
redhat quarkus
|
resteasy quarkus
|
A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentially sensitive information when the server got WebApplicatio…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-25633
|
2024-11-21 14:18 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208648
|
7.5 |
HIGH
Network
|
misp
|
misp
|
An issue was discovered in MISP before 2.4.132. It can perform an unwanted action because of a POST operation on a form that is not linked to the login page.
|
NVD-CWE-noinfo
|
CVE-2020-25766
|
2024-11-21 14:18 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208649
|
9.8 |
CRITICAL
Network
|
cesanta
|
mongoose
|
A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of bounds checking. A crafted HTTP header can exploit this bug. NOTE: a committer has …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-25756
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208650
|
8.8 |
HIGH
Network
|
corephp
|
pago_commerce
|
The paGO Commerce plugin 2.5.9.0 for Joomla! allows SQL Injection via the administrator/index.php?option=com_pago&view=comments filter_published parameter.
|
CWE-89
SQL Injection
|
CVE-2020-25751
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|