|
198391
|
9.8 |
CRITICAL
Network
|
solarwinds
|
serv-u
|
SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.
|
NVD-CWE-Other
|
CVE-2020-35481
|
2024-11-21 14:27 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198392
|
6.5 |
MEDIUM
Network
|
digium
|
asterisk
|
An issue was discovered in res_pjsip_diversion.c in Sangoma Asterisk before 13.38.0, 14.x through 16.x before 16.15.0, 17.x before 17.9.0, and 18.x before 18.1.0. A crash can occur when a SIP message…
|
NVD-CWE-noinfo
|
CVE-2020-35652
|
2024-11-21 14:27 |
2021-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198393
|
9.1 |
CRITICAL
Network
|
mitel
|
micollab
|
A library index page in NuPoint Messenger in Mitel MiCollab before 9.2 FP1 could allow an unauthenticated attacker to gain access (view and modify) to user data.
|
NVD-CWE-noinfo
|
CVE-2020-35547
|
2024-11-21 14:27 |
2021-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198394
|
8.2 |
HIGH
Local
|
qemu
|
qemu
|
A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared di…
|
-
|
CVE-2020-35517
|
2024-11-21 14:27 |
2021-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198395
|
8.8 |
HIGH
Network
|
tp-link
|
tl-wr841n_firmware
|
A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users to execute arbitrary code as root via shell metacha…
|
CWE-78
OS Command
|
CVE-2020-35576
|
2024-11-21 14:27 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198396
|
4.9 |
MEDIUM
Network
|
linux redhat
|
linux_kernel enterprise_linux
|
A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if b…
|
-
|
CVE-2020-35513
|
2024-11-21 14:27 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198397
|
4.8 |
MEDIUM
Network
|
bakeshop_online_ordering_system_project
|
bakeshop_online_ordering_system
|
Bakeshop Online Ordering System in PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to inject an arbitrary web script or HTML in admin dashboard - "Categories".
|
CWE-79
Cross-site Scripting
|
CVE-2020-35309
|
2024-11-21 14:27 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198398
|
9.1 |
CRITICAL
Network
|
student_result_management_system_project
|
student_result_management_system
|
Student Result Management System In PHP With Source Code is affected by SQL injection. An attacker can able to access of Admin Panel and manage every account of Result.
|
CWE-89
SQL Injection
|
CVE-2020-35270
|
2024-11-21 14:27 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198399
|
9.8 |
CRITICAL
Network
|
egavilanmedia
|
user_registration_and_login_system_with_admin_panel
|
EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.
|
CWE-89
SQL Injection
|
CVE-2020-35263
|
2024-11-21 14:27 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198400
|
8.8 |
HIGH
Network
|
cakefoundation
|
cakephp
|
A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks by changing the HTTP request method to a…
|
CWE-352
Origin Validation Error
|
CVE-2020-35239
|
2024-11-21 14:27 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|