|
196011
|
5.3 |
MEDIUM
Network
|
labvantage
|
labvantage
|
LabVantage LIMS 8.3 does not properly maintain the confidentiality of database names. For example, the web application exposes the database name. An attacker might be able to enumerate database names…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-7959
|
2024-11-21 14:38 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196012
|
9.8 |
CRITICAL
Network
|
horde fedoraproject debian
|
groupware fedora debian_linux
|
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
|
CWE-94
Code Injection
|
CVE-2020-8518
|
2024-11-21 14:38 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196013
|
9.8 |
CRITICAL
Network
|
unitrends
|
backup
|
In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that resulted in an authentication bypass.
|
CWE-89
SQL Injection
|
CVE-2020-8427
|
2024-11-21 14:38 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196014
|
9.8 |
CRITICAL
Network
|
script-manager_project
|
script-manager
|
An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execute arbitrary code.
|
CWE-94
Code Injection
|
CVE-2020-8129
|
2024-11-21 14:38 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196015
|
9.8 |
CRITICAL
Network
|
jsreport
|
jsreport
|
An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitrary code.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-8128
|
2024-11-21 14:38 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196016
|
5.3 |
MEDIUM
Network
|
dovecot fedoraproject
|
dovecot fedora
|
The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet and a trailing > character exists. This causes a den…
|
CWE-20
Improper Input Validation
|
CVE-2020-7957
|
2024-11-21 14:38 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196017
|
8.8 |
HIGH
Network
|
kinetica
|
kinetica
|
The Admin web application in Kinetica 7.0.9.2.20191118151947 does not properly sanitise the input for the function getLogs. This lack of sanitisation could be exploited to allow an authenticated atta…
|
CWE-78
OS Command
|
CVE-2020-8429
|
2024-11-21 14:38 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196018
|
5.4 |
MEDIUM
Network
|
piwigo
|
piwigo
|
Piwigo 2.10.1 is affected by stored XSS via the Group Name Field to the group_list page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8089
|
2024-11-21 14:38 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196019
|
7.8 |
HIGH
Local
|
ui
|
edgeswitch
|
A privilege escalation in the EdgeSwitch prior to version 1.7.1, an CGI script don't fully sanitize the user input resulting in local commands execution, allowing an operator user (Privilege-1) to es…
|
CWE-78
OS Command
|
CVE-2020-8126
|
2024-11-21 14:38 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196020
|
7.8 |
HIGH
Local
|
opservices
|
opmon
|
An issue was discovered in OpServices OpMon 9.3.2. Starting from the apache user account, it is possible to perform privilege escalation through the lack of correct configuration in the server's sudo…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-7954
|
2024-11-21 14:38 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|