|
210041
|
7.5 |
HIGH
Network
|
file_transfer_ifamily_project
|
file_transfer_ifamily
|
DONG JOO CHO File Transfer iFamily 2.1 allows directory traversal related to the ./etc/ path.
|
CWE-22
Path Traversal
|
CVE-2020-12128
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210042
|
8.2 |
HIGH
Network
|
binance
|
tss-lib
|
The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a signing round or obtain sensitive information fro…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-12118
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210043
|
6.1 |
MEDIUM
Network
|
bigbluebutton
|
bigbluebutton
|
BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12113
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210044
|
7.5 |
HIGH
Network
|
bigbluebutton
|
bigbluebutton
|
BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.
|
CWE-22
Path Traversal
|
CVE-2020-12112
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210045
|
5.9 |
MEDIUM
Network
|
infradead opensuse
|
openconnect leap
|
OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers in performing man-in-the-middle attacks.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-12105
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210046
|
6.1 |
MEDIUM
Network
|
catchplugins
|
catch_breadcrumb
|
The Catch Breadcrumb plugin before 1.5.4 for WordPress allows Reflected XSS via the s parameter (a search query). Also affected are 16 themes (if the plugin is enabled) by the same author: Alchemist …
|
CWE-79
Cross-site Scripting
|
CVE-2020-12054
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210047
|
10.0 |
CRITICAL
Network
|
beakerbrowser
|
beaker
|
Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-p…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-12079
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210048
|
8.8 |
HIGH
Network
|
mappresspro
|
mappress
|
The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or capability checks), leading to remote code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-12077
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210049
|
8.8 |
HIGH
Network
|
supsystic
|
data_tables_generator
|
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS.
|
CWE-352
Origin Validation Error
|
CVE-2020-12076
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210050
|
8.8 |
HIGH
Network
|
supsystic
|
data_tables_generator
|
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-12075
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|