|
209981
|
9.8 |
CRITICAL
Network
|
mono
|
monox
|
MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because of deserialization in ModuleGallery.HTML5Upload, ModuleGaller…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-12471
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209982
|
7.2 |
HIGH
Network
|
mono
|
monox
|
MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template.
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2020-12470
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209983
|
6.5 |
MEDIUM
Network
|
intelliants
|
subrion
|
admin/blocks.php in Subrion CMS through 4.2.1 allows PHP Object Injection (with resultant file deletion) via serialized data in the subpages value within a block to blocks/edit.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-12469
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209984
|
7.8 |
HIGH
Local
|
intelliants
|
subrion
|
Subrion CMS 4.2.1 allows CSV injection via a phrase value within a language. This is related to phrases/add/ and languages/download/.
|
NVD-CWE-Other
|
CVE-2020-12468
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209985
|
6.5 |
MEDIUM
Network
|
intelliants
|
subrion
|
Subrion CMS 4.2.1 allows session fixation via an alphanumeric value in a session cookie.
|
CWE-384
Session Fixation
|
CVE-2020-12467
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209986
|
7.2 |
HIGH
Network
|
mono
|
monox
|
MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting from ffmpeg.exe to a different program.
|
NVD-CWE-noinfo
|
CVE-2020-12473
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209987
|
5.4 |
MEDIUM
Network
|
mono
|
monox
|
MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12472
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209988
|
6.7 |
MEDIUM
Local
|
linux netapp
|
linux_kernel cloud_backup steelstore_cloud_integrated_storage hci_storage_nodes aff_a700s active_iq_unified_manager hci_compute_node solidfire_\&_hci_storage_node solidfir…
|
usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925.
|
CWE-416
Use After Free
|
CVE-2020-12464
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209989
|
6.7 |
MEDIUM
Local
|
linux netapp
|
linux_kernel cloud_backup steelstore_cloud_integrated_storage solidfire_\&_hci_management_node active_iq_unified_manager hci_compute_node solidfire_baseboard_management_controll…
|
An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10, aka CID-b102f0c522cf. An oversized packet with too many rx fragmen…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-12465
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209990
|
6.1 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms
|
The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.
|
CWE-352
Origin Validation Error
|
CVE-2020-12462
|
2024-11-21 13:59 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|