|
198511
|
7.2 |
HIGH
Network
|
jaws_project
|
jaws
|
Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?reqGadget=Components&reqAction=InstallGadget&comp=FileBrowser and admin.php?reqGad…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-35656
|
2024-11-21 14:27 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198512
|
5.5 |
MEDIUM
Local
|
microsoft
|
azure_sphere
|
A denial-of-service vulnerability exists in the asynchronous ioctl functionality of Microsoft Azure Sphere 20.05. A sequence of specially crafted ioctl calls can cause a denial of service. An attacke…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-35609
|
2024-11-21 14:27 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198513
|
7.8 |
HIGH
Local
|
microsoft
|
azure_sphere
|
A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted AF_PACKET socket can cause a process to create an …
|
CWE-74
Injection
|
CVE-2020-35608
|
2024-11-21 14:27 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198514
|
8.8 |
HIGH
Network
|
mediawiki
|
mediawiki
|
An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks agains…
|
CWE-352
Origin Validation Error
|
CVE-2020-35626
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198515
|
8.8 |
HIGH
Network
|
mediawiki
|
mediawiki
|
An issue was discovered in the Widgets extension for MediaWiki through 1.35.1. Any user with the ability to edit pages within the Widgets namespace could call any static function within any class (de…
|
CWE-862
Missing Authorization
|
CVE-2020-35625
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198516
|
5.3 |
MEDIUM
Network
|
mediawiki
|
mediawiki
|
An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may provide unintended clues about how a voting process…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-35624
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198517
|
7.5 |
HIGH
Network
|
mediawiki
|
mediawiki
|
An issue was discovered in the CasAuth extension for MediaWiki through 1.35.1. Due to improper username validation, it allowed user impersonation with trivial manipulations of certain characters with…
|
CWE-20 CWE-706
Improper Input Validation Use of Incorrectly-Resolved Name or Reference
|
CVE-2020-35623
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198518
|
6.1 |
MEDIUM
Network
|
mediawiki
|
mediawiki
|
An issue was discovered in the GlobalUsage extension for MediaWiki through 1.35.1. SpecialGlobalUsage.php calls WikiMap::makeForeignLink unsafely. The $page variable within the formatItem function wa…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35622
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198519
|
8.8 |
HIGH
Network
|
webmin
|
webmin
|
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C…
|
CWE-78
OS Command
|
CVE-2020-35606
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198520
|
9.8 |
CRITICAL
Network
|
kitty_project debian
|
kitty debian_linux
|
The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error messa…
|
NVD-CWE-Other
|
CVE-2020-35605
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|