|
208381
|
8.8 |
HIGH
Network
|
observium
|
observium
|
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted po…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2020-25133
|
2024-11-21 14:17 |
2020-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208382
|
9.8 |
CRITICAL
Network
|
observium
|
observium
|
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL statements in malfo…
|
CWE-89
SQL Injection
|
CVE-2020-25132
|
2024-11-21 14:17 |
2020-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208383
|
6.1 |
MEDIUM
Network
|
observium
|
observium
|
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious …
|
CWE-79
Cross-site Scripting
|
CVE-2020-25131
|
2024-11-21 14:17 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208384
|
6.5 |
MEDIUM
Network
|
observium
|
observium
|
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL statements in malfo…
|
CWE-89
SQL Injection
|
CVE-2020-25130
|
2024-11-21 14:17 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208385
|
5.0 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-25085
|
2024-11-21 14:17 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208386
|
3.2 |
LOW
Local
|
qemu debian
|
qemu debian_linux
|
QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not checked.
|
CWE-416
Use After Free
|
CVE-2020-25084
|
2024-11-21 14:17 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208387
|
9.8 |
CRITICAL
Network
|
sophos
|
unified_threat_management
|
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
|
CWE-78
OS Command
|
CVE-2020-25223
|
2024-11-21 14:17 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208388
|
5.5 |
MEDIUM
Local
|
framer
|
framer_preview
|
The Framer Preview application 12 for Android exposes com.framer.viewer.FramerViewActivity to other applications. By calling the intent with the action set to android.intent.action.VIEW, any other ap…
|
NVD-CWE-Other
|
CVE-2020-25203
|
2024-11-21 14:17 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208389
|
9.8 |
CRITICAL
Network
|
yworks
|
yed
|
yWorks yEd Desktop before 3.20.1 allows code execution via an XSL Transformation when using an XML file in conjunction with a custom stylesheet.
|
CWE-91
Blind XPath Injection
|
CVE-2020-25216
|
2024-11-21 14:17 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208390
|
9.8 |
CRITICAL
Network
|
yworks
|
yed
|
yWorks yEd Desktop before 3.20.1 allows XXE attacks via an XML or GraphML document.
|
CWE-611
XXE
|
CVE-2020-25215
|
2024-11-21 14:17 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|