|
197551
|
7.5 |
HIGH
Network
|
buddypress
|
buddypress
|
In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. This has been patched in version 5.1.2.
|
CWE-200
Information Exposure
|
CVE-2020-5244
|
2024-11-21 14:33 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197552
|
6.5 |
MEDIUM
Network
|
dnnsoftware
|
dotnetnuke
|
DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
|
CWE-669 CWE-434
Incorrect Resource Transfer Between Spheres Unrestricted Upload of File with Dangerous Type
|
CVE-2020-5188
|
2024-11-21 14:33 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197553
|
8.8 |
HIGH
Network
|
dnnsoftware
|
dotnetnuke
|
DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).
|
CWE-22
Path Traversal
|
CVE-2020-5187
|
2024-11-21 14:33 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197554
|
5.4 |
MEDIUM
Network
|
dnnsoftware
|
dotnetnuke
|
DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).
|
CWE-79
Cross-site Scripting
|
CVE-2020-5186
|
2024-11-21 14:33 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197555
|
7.5 |
HIGH
Network
|
uap-core_project
|
uap-core
|
uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regexes are vulnerable to regular expression denial of service (REDoS) due to overla…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2020-5243
|
2024-11-21 14:33 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197556
|
8.8 |
HIGH
Network
|
openhab
|
openhab
|
openHAB before 2.5.2 allow a remote attacker to use REST calls to install the EXEC binding or EXEC transformation service and execute arbitrary commands on the system with the privileges of the user …
|
CWE-863
Incorrect Authorization
|
CVE-2020-5242
|
2024-11-21 14:33 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197557
|
5.3 |
MEDIUM
Physics
|
dell
|
chengming_3980_firmware g3_3579_firmware g3_3590_firmware g3_3779_firmware g5_5587_firmware g5_5590_firmware g7_7588_firmware g7_7590_firmware g7_7790_firmware embedded_box…
|
Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu. An attacker with phy…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-5326
|
2024-11-21 14:33 |
2020-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197558
|
4.4 |
MEDIUM
Local
|
dell
|
g3_3579_firmware g3_3779_firmware g3_15_3590_firmware g5_15_5590_firmware g5_5090_firmware g5_5587_firmware g7_15_7590_firmware g7_17_7790_firmware g7_7588_firmware inspiro…
|
Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being ex…
|
CWE-59
Link Following
|
CVE-2020-5324
|
2024-11-21 14:33 |
2020-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197559
|
8.8 |
HIGH
Network
|
mailu
|
mailu
|
In Mailu before version 1.7, an authenticated user can exploit a vulnerability in Mailu fetchmail script and gain full access to a Mailu instance. Mailu servers that have open registration or untrust…
|
NVD-CWE-noinfo
|
CVE-2020-5239
|
2024-11-21 14:33 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197560
|
5.4 |
MEDIUM
Network
|
matestack
|
ui-core
|
matestack-ui-core (RubyGem) before 0.7.4 is vulnerable to XSS/Script injection. This vulnerability is patched in version 0.7.4.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5241
|
2024-11-21 14:33 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|