|
196591
|
6.8 |
MEDIUM
Network
|
gilacms
|
gila_cms
|
Gila CMS 1.11.8 allows /admin/media?path=../ Path Traversal.
|
CWE-22
Path Traversal
|
CVE-2020-5512
|
2024-11-21 14:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196592
|
7.2 |
HIGH
Network
|
gilacms
|
gila_cms
|
Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2020-5515
|
2024-11-21 14:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196593
|
9.1 |
CRITICAL
Network
|
gilacms
|
gila_cms
|
Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-5514
|
2024-11-21 14:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196594
|
7.5 |
HIGH
Network
|
hashbrowncms
|
hashbrown_cms
|
An issue was discovered in HashBrown CMS before 1.3.2. Server/Entity/Resource/Connection.js allows an attacker to reach a parent directory via a crafted name or ID field.
|
CWE-22
Path Traversal
|
CVE-2020-5840
|
2024-11-21 14:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196595
|
9.8 |
CRITICAL
Network
|
litespeedtech
|
openlitespeed
|
The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App" screen.
|
CWE-20
Improper Input Validation
|
CVE-2020-5519
|
2024-11-21 14:34 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196596
|
9.8 |
CRITICAL
Network
|
apache
|
rust_sgx_sdk
|
Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two global IDs are the same.
|
NVD-CWE-noinfo
|
CVE-2020-5499
|
2024-11-21 14:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196597
|
6.1 |
MEDIUM
Network
|
mitreid
|
connect
|
The OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being included in the page unsanitized. This is related to header.tag. The issue can be ex…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5497
|
2024-11-21 14:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196598
|
8.8 |
HIGH
Network
|
fontforge opensuse
|
fontforge leap
|
FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-5496
|
2024-11-21 14:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196599
|
8.8 |
HIGH
Network
|
fontforge fedoraproject opensuse
|
fontforge fedora leap
|
FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.
|
CWE-416
Use After Free
|
CVE-2020-5395
|
2024-11-21 14:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196600
|
5.3 |
MEDIUM
Network
|
ibm
|
safer_payments
|
IBM Counter Fraud Management for Safer Payments 5.7.0.00 through 5.7.0.10, 6.0.0.00 through 6.0.0.07, 6.1.0.00 through 6.1.0.05, and 6.2.0.00 through 6.2.1.00 could allow an authenticated attacker un…
|
NVD-CWE-noinfo
|
CVE-2020-4729
|
2024-11-21 14:33 |
2023-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|