|
196091
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8421
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196092
|
8.8 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.
|
CWE-352
Origin Validation Error
|
CVE-2020-8420
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196093
|
8.8 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.
|
CWE-352
Origin Validation Error
|
CVE-2020-8419
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196094
|
8.8 |
HIGH
Network
|
codesnippets
|
code_snippets
|
The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.
|
CWE-352
Origin Validation Error
|
CVE-2020-8417
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196095
|
5.5 |
MEDIUM
Local
|
python
|
python
|
In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-8315
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196096
|
8.8 |
HIGH
Network
|
uclouvain debian
|
openjpeg debian_linux
|
opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-8112
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196097
|
9.8 |
CRITICAL
Network
|
prosody debian
|
mod_auth_ldap2 mod_auth_ldap debian_linux
|
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only fu…
|
CWE-863
Incorrect Authorization
|
CVE-2020-8086
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196098
|
5.4 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue. Any user can modify…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7934
|
2024-11-21 14:38 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196099
|
8.8 |
HIGH
Network
|
super_file_explorer_project
|
super_file_explorer
|
An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the r…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-7998
|
2024-11-21 14:38 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196100
|
6.1 |
MEDIUM
Network
|
asus
|
rt-ac66u_firmware
|
ASUS WRT-AC66U 3 RT 3.0.0.4.372_67 devices allow XSS via the Client Name field to the Parental Control feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7997
|
2024-11-21 14:38 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|