|
196211
|
9.8 |
CRITICAL
Network
|
script-manager_project
|
script-manager
|
An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execute arbitrary code.
|
CWE-94
Code Injection
|
CVE-2020-8129
|
2024-11-21 14:38 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196212
|
9.8 |
CRITICAL
Network
|
jsreport
|
jsreport
|
An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitrary code.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-8128
|
2024-11-21 14:38 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196213
|
5.3 |
MEDIUM
Network
|
dovecot fedoraproject
|
dovecot fedora
|
The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet and a trailing > character exists. This causes a den…
|
CWE-20
Improper Input Validation
|
CVE-2020-7957
|
2024-11-21 14:38 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196214
|
8.8 |
HIGH
Network
|
kinetica
|
kinetica
|
The Admin web application in Kinetica 7.0.9.2.20191118151947 does not properly sanitise the input for the function getLogs. This lack of sanitisation could be exploited to allow an authenticated atta…
|
CWE-78
OS Command
|
CVE-2020-8429
|
2024-11-21 14:38 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196215
|
5.4 |
MEDIUM
Network
|
piwigo
|
piwigo
|
Piwigo 2.10.1 is affected by stored XSS via the Group Name Field to the group_list page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8089
|
2024-11-21 14:38 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196216
|
7.8 |
HIGH
Local
|
ui
|
edgeswitch
|
A privilege escalation in the EdgeSwitch prior to version 1.7.1, an CGI script don't fully sanitize the user input resulting in local commands execution, allowing an operator user (Privilege-1) to es…
|
CWE-78
OS Command
|
CVE-2020-8126
|
2024-11-21 14:38 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196217
|
7.8 |
HIGH
Local
|
opservices
|
opmon
|
An issue was discovered in OpServices OpMon 9.3.2. Starting from the apache user account, it is possible to perform privilege escalation through the lack of correct configuration in the server's sudo…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-7954
|
2024-11-21 14:38 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196218
|
7.5 |
HIGH
Network
|
opservices
|
opmon
|
An issue was discovered in OpServices OpMon 9.3.2. Without authentication, it is possible to read server files (e.g., /etc/passwd) due to the use of the nmap -iL (aka input file) option.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-7953
|
2024-11-21 14:38 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196219
|
7.5 |
HIGH
Network
|
percona
|
monitoring_and_management
|
pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-7920
|
2024-11-21 14:38 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196220
|
7.5 |
HIGH
Network
|
rogersmedia
|
citytv_video
|
The Citytv Video application 4.08.0 for Android and 3.35 for iOS sends Unencrypted Analytics.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-8507
|
2024-11-21 14:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|