|
200821
|
9.8 |
CRITICAL
Network
|
infinitewp
|
infinitewp
|
In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it easier for remote attackers to conduct admin Account Takeover attacks.
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2020-28642
|
2024-11-21 14:23 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200822
|
9.8 |
CRITICAL
Network
|
dyne
|
tomb
|
ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing affected users' files to be encrypted with "tomb {W] Detected DISPLAY, but only …
|
CWE-287
Improper Authentication
|
CVE-2020-28638
|
2024-11-21 14:23 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200823
|
8.8 |
HIGH
Network
|
togglz
|
togglz
|
The console in Togglz before 2.9.4 allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-28191
|
2024-11-21 14:22 |
2022-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200824
|
7.8 |
HIGH
Local
|
beyondtrust
|
privilege_management_for_windows
|
In BeyondTrust Privilege Management for Windows (aka PMfW) through 5.7, a SYSTEM installation causes Cryptbase.dll to be loaded from the user-writable location %WINDIR%\Temp.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-28369
|
2024-11-21 14:22 |
2023-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200825
|
7.1 |
HIGH
Local
|
swtpm_project
|
swtpm
|
In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.
|
CWE-59
Link Following
|
CVE-2020-28407
|
2024-11-21 14:22 |
2023-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200826
|
6.5 |
MEDIUM
Network
|
libdwarf_project
|
libdwarf
|
libdwarf before 20201201 allows a dwarf_print_lines.c NULL pointer dereference and application crash via a DWARF5 line-table header that has an invalid FORM for a pathname.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-28163
|
2024-11-21 14:22 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200827
|
9.8 |
CRITICAL
Network
|
npos-tesseract_project
|
npos-tesseract
|
This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.
|
CWE-77
Command Injection
|
CVE-2020-28453
|
2024-11-21 14:22 |
2022-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200828
|
9.8 |
CRITICAL
Network
|
image-tiler_project
|
image-tiler
|
This affects the package image-tiler before 2.0.2.
|
CWE-77
Command Injection
|
CVE-2020-28451
|
2024-11-21 14:22 |
2022-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200829
|
9.8 |
CRITICAL
Network
|
heroku-env_project
|
heroku-env
|
This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.
|
CWE-77
Command Injection
|
CVE-2020-28437
|
2024-11-21 14:22 |
2022-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200830
|
9.8 |
CRITICAL
Network
|
gitblame_project
|
gitblame
|
This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.
|
CWE-77
Command Injection
|
CVE-2020-28434
|
2024-11-21 14:22 |
2022-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|