|
208281
|
6.5 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On-Behalf-Of. The authorization checks are performed for the actual user and not …
|
CWE-863
Incorrect Authorization
|
CVE-2020-26029
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208282
|
4.9 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets.
|
CWE-863
Incorrect Authorization
|
CVE-2020-26028
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208283
|
10.0 |
CRITICAL
Network
|
browserup
|
browserup_proxy
|
BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data as a HAR file. BrowserUp Proxy works well as a standalone proxy server, but it …
|
-
|
CVE-2020-26282
|
2024-11-21 14:19 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208284
|
8.5 |
HIGH
Network
|
gohugo
|
hugo
|
Hugo is a fast and Flexible Static Site Generator built in Go. Hugo depends on Go's `os/exec` for certain features, e.g. for rendering of Pandoc documents if these binaries are found in the system `%…
|
CWE-78
OS Command
|
CVE-2020-26284
|
2024-11-21 14:19 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208285
|
7.5 |
HIGH
Network
|
rust-lang
|
async-h1
|
async-h1 is an asynchronous HTTP/1.1 parser for Rust (crates.io). There is a request smuggling vulnerability in async-h1 before version 2.3.0. This vulnerability affects any webserver that uses async…
|
-
|
CVE-2020-26281
|
2024-11-21 14:19 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208286
|
6.1 |
MEDIUM
Network
|
dbdeployer
|
dbdeployer
|
DBdeployer is a tool that deploys MySQL database servers easily. In DBdeployer before version 1.58.2, users unpacking a tarball may use a maliciously packaged tarball that contains symlinks to files …
|
-
|
CVE-2020-26277
|
2024-11-21 14:19 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208287
|
5.3 |
MEDIUM
Network
|
wireshark oracle
|
wireshark zfs_storage_appliance_kit
|
Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted capture file
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-26422
|
2024-11-21 14:19 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208288
|
6.1 |
MEDIUM
Network
|
jupyter
|
jupyter_server
|
The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. In Jupyter Server before version …
|
-
|
CVE-2020-26275
|
2024-11-21 14:19 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208289
|
7.5 |
HIGH
Network
|
tlslite-ng_project
|
tlslite-ng
|
tlslite-ng is an open source python library that implements SSL and TLS cryptographic protocols. In tlslite-ng before versions 0.7.6 and 0.8.0-alpha39, the code that performs decryption and padding c…
|
-
|
CVE-2020-26263
|
2024-11-21 14:19 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208290
|
6.1 |
MEDIUM
Network
|
niftypm
|
nifty-pm
|
Nifty-PM CPE 2.3 is affected by stored HTML injection. The impact is remote arbitrary code execution.
|
CWE-79
Cross-site Scripting
|
CVE-2020-26049
|
2024-11-21 14:19 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|