|
198711
|
7.5 |
HIGH
Network
|
mediawiki debian fedoraproject
|
mediawiki debian_linux fedora
|
In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits Special:UserRights but does not have rights to ch…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35475
|
2024-11-21 14:27 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198712
|
6.1 |
MEDIUM
Network
|
mediawiki fedoraproject
|
mediawiki fedora
|
In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-legend-watchlistexpiry can be changed onwiki so that t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35474
|
2024-11-21 14:27 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198713
|
9.8 |
CRITICAL
Network
|
spotweb_project
|
spotweb
|
Time-based SQL injection exists in Spotweb 1.4.9 via the query string.
|
CWE-89
SQL Injection
|
CVE-2020-35545
|
2024-11-21 14:27 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198714
|
8.1 |
HIGH
Network
|
fasterxml netapp debian oracle
|
jackson-databind service_level_manager debian_linux webcenter_portal application_testing_suite banking_platform agile_plm sd-wan_edge communications_services_gatekeeper ret…
|
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-35491
|
2024-11-21 14:27 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198715
|
8.1 |
HIGH
Network
|
fasterxml netapp debian oracle
|
jackson-databind service_level_manager debian_linux webcenter_portal application_testing_suite banking_platform agile_plm communications_services_gatekeeper retail_merchandisi…
|
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-35490
|
2024-11-21 14:27 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198716
|
10.0 |
CRITICAL
Network
|
rocklobster
|
contact_form_7
|
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-35489
|
2024-11-21 14:27 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198717
|
5.3 |
MEDIUM
Network
|
hashicorp
|
vault
|
HashiCorp Vault Enterprise’s Sentinel EGP policy feature incorrectly allowed requests to be processed in parent and sibling namespaces. Fixed in 1.5.6 and 1.6.1.
|
NVD-CWE-noinfo
|
CVE-2020-35453
|
2024-11-21 14:27 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198718
|
9.8 |
CRITICAL
Network
|
opentsdb
|
opentsdb
|
A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written to a gnuplot file in the /tmp directory. This file is…
|
CWE-78
OS Command
|
CVE-2020-35476
|
2024-11-21 14:27 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198719
|
9.8 |
CRITICAL
Network
|
softwareag
|
terracotta_server_oss
|
The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed using affected versions of the Terracotta Server OSS container may allow a remot…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-35469
|
2024-11-21 14:27 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198720
|
9.8 |
CRITICAL
Network
|
appbase
|
streams
|
The Appbase streams Docker image 2.1.2 contains a blank password for the root user. Systems deployed using affected versions of the streams container may allow a remote attacker to achieve root acces…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-35468
|
2024-11-21 14:27 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|