|
208441
|
9.8 |
CRITICAL
Network
|
foxitsoftware
|
foxit_reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Field::ClearItems and Field::DeleteOptions, during AcroForm JavaScript execution.
|
CWE-416
Use After Free
|
CVE-2020-26534
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208442
|
5.3 |
MEDIUM
Network
|
filecloud
|
filecloud
|
CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.
|
NVD-CWE-noinfo
|
CVE-2020-26524
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208443
|
6.1 |
MEDIUM
Network
|
froala
|
froala_editor
|
Froala Editor before 3.2.2 allows XSS via pasted content.
|
CWE-79
Cross-site Scripting
|
CVE-2020-26523
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208444
|
- |
|
-
|
-
|
Dotmesh is a git-like command-line interface for capturing, organizing and sharing application states. In versions 0.8.1 and prior, the unsafe handling of symbolic links in an unpacking routine may
…
|
-
|
CVE-2020-26312
|
2024-11-21 14:19 |
2024-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208445
|
9.8 |
CRITICAL
Network
|
evenbalance
|
punkbuster
|
Directory Traversal vulnerability in Server functionalty in Even Balance Punkbuster version 1.902 before 1.905 allows remote attackers to execute arbitrary code.
|
CWE-22
Path Traversal
|
CVE-2020-26037
|
2024-11-21 14:19 |
2023-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208446
|
5.3 |
MEDIUM
Network
|
cisco
|
asyncos
|
A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass content filters that are c…
|
NVD-CWE-noinfo
|
CVE-2020-26082
|
2024-11-21 14:19 |
2023-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208447
|
6.5 |
MEDIUM
Network
|
cisco
|
catalyst_sd-wan_manager
|
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensit…
|
CWE-22
Path Traversal
|
CVE-2020-26065
|
2024-11-21 14:19 |
2023-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208448
|
8.1 |
HIGH
Network
|
cisco
|
catalyst_sd-wan_manager
|
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system.
The v…
|
CWE-611
XXE
|
CVE-2020-26064
|
2024-11-21 14:19 |
2023-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208449
|
9.8 |
CRITICAL
Network
|
gnuplot_project
|
gnuplot
|
gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest().
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-25969
|
2024-11-21 14:19 |
2023-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208450
|
7.5 |
HIGH
Network
|
is.js_project
|
is.js
|
is.js is a general-purpose check library. Versions 0.9.0 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). is.js uses a regex copy…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2020-26302
|
2024-11-21 14:19 |
2022-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|