|
209951
|
8.8 |
HIGH
Network
|
sonatype
|
nexus_repository_manager_3
|
An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks withou…
|
CWE-863
Incorrect Authorization
|
CVE-2020-11753
|
2024-11-21 13:58 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209952
|
6.1 |
MEDIUM
Network
|
python-markdown2_project
|
python-markdown2
|
python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11888
|
2024-11-21 13:58 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209953
|
6.1 |
MEDIUM
Network
|
gtranslate
|
translate_wordpress_with_gtranslate
|
The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11930
|
2024-11-21 13:58 |
2020-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209954
|
9.8 |
CRITICAL
Network
|
davidlingren
|
media_library_assistant
|
In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin.
|
NVD-CWE-noinfo
|
CVE-2020-11928
|
2024-11-21 13:58 |
2020-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209955
|
9.1 |
CRITICAL
Network
|
libming
|
libming
|
Ming (aka libming) 0.4.8 has a heap-based buffer over-read (2 bytes) in the function decompileIF() in decompile.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-11895
|
2024-11-21 13:58 |
2020-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209956
|
9.1 |
CRITICAL
Network
|
libming
|
libming
|
Ming (aka libming) 0.4.8 has a heap-based buffer over-read (8 bytes) in the function decompileIF() in decompile.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-11894
|
2024-11-21 13:58 |
2020-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209957
|
6.1 |
MEDIUM
Network
|
svg2png_project
|
svg2png
|
svg2png 4.1.1 allows XSS with resultant SSRF via JavaScript inside an SVG document.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11887
|
2024-11-21 13:58 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209958
|
8.1 |
HIGH
Network
|
opennms
|
horizon meridian
|
OpenNMS Horizon and Meridian allows HQL Injection in element/nodeList.htm (aka the NodeListController) via snmpParm or snmpParmValue to addCriteriaForSnmpParm. This affects Horizon before 25.2.1, Mer…
|
CWE-89
SQL Injection
|
CVE-2020-11886
|
2024-11-21 13:58 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209959
|
7.2 |
HIGH
Network
|
wso2
|
enterprise_integrator
|
WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintended network invocations such as SSRF via an uploade…
|
CWE-611 CWE-918
XXE Server-Side Request Forgery (SSRF)
|
CVE-2020-11885
|
2024-11-21 13:58 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209960
|
5.3 |
MEDIUM
Network
|
divante
|
storefront-api vue-storefront-api
|
In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpected HTTP requests lead to an exception that discloses the error stack trace, wit…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-11883
|
2024-11-21 13:58 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|