|
208331
|
7.5 |
HIGH
Network
|
mediawiki fedoraproject
|
mediawiki fedora
|
An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even when the target page is protected against "page creation" and the attacker should…
|
CWE-863
Incorrect Authorization
|
CVE-2020-26121
|
2024-11-21 14:19 |
2020-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208332
|
6.1 |
MEDIUM
Network
|
mediawiki fedoraproject
|
mediawiki fedora
|
XSS exists in the MobileFrontend extension for MediaWiki before 1.34.4 because section.line is mishandled during regex section line replacement from PageGateway. Using crafted HTML, an attacker can e…
|
CWE-79
Cross-site Scripting
|
CVE-2020-26120
|
2024-11-21 14:19 |
2020-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208333
|
8.1 |
HIGH
Network
|
tigervnc debian opensuse
|
tigervnc debian_linux leap
|
In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a cert…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-26117
|
2024-11-21 14:19 |
2020-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208334
|
7.2 |
HIGH
Network
|
python fedoraproject canonical netapp debian oracle opensuse
|
python fedora ubuntu_linux solidfire hci_storage_node debian_linux zfs_storage_appliance_kit leap
|
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by ins…
|
CWE-74
Injection
|
CVE-2020-26116
|
2024-11-21 14:19 |
2020-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208335
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 90.0.10 allows self XSS via the Cron Editor interface (SEC-574).
|
CWE-79
Cross-site Scripting
|
CVE-2020-26115
|
2024-11-21 14:19 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208336
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 90.0.10 allows self XSS via the Cron Jobs interface (SEC-573).
|
CWE-79
Cross-site Scripting
|
CVE-2020-26114
|
2024-11-21 14:19 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208337
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569).
|
CWE-79
Cross-site Scripting
|
CVE-2020-26113
|
2024-11-21 14:19 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208338
|
7.5 |
HIGH
Network
|
cpanel
|
cpanel
|
The email quota cache in cPanel before 90.0.10 allows overwriting of files.
|
NVD-CWE-noinfo
|
CVE-2020-26112
|
2024-11-21 14:19 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208339
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566).
|
CWE-79
Cross-site Scripting
|
CVE-2020-26111
|
2024-11-21 14:19 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208340
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564).
|
CWE-79
Cross-site Scripting
|
CVE-2020-26110
|
2024-11-21 14:19 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|