|
210891
|
6.1 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1
|
CWE-79
Cross-site Scripting
|
CVE-2020-13267
|
2024-11-21 14:00 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210892
|
9.8 |
CRITICAL
Network
|
anydesk
|
anydesk
|
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2020-13160
|
2024-11-21 14:00 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210893
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permissions of other users' deploy keys under certain conditions
|
CWE-862
Missing Authorization
|
CVE-2020-13266
|
2024-11-21 14:00 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210894
|
9.8 |
CRITICAL
Network
|
codedropz
|
drag_and_drop_multiple_file_upload_-_contact_form_7
|
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-12800
|
2024-11-21 14:00 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210895
|
6.5 |
MEDIUM
Network
|
libreoffice opensuse fedoraproject
|
libreoffice leap fedora
|
ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable f…
|
CWE-20
Improper Input Validation
|
CVE-2020-12803
|
2024-11-21 14:00 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210896
|
7.5 |
HIGH
Network
|
ui w1.fi asus broadcom canon cisco dlink dell epson hp huawei nec netgear ruckussecurity tp-link zte zyxel microsoft fedoraproject debian canonical
|
unifi_controller hostapd rt-n11 adsl selphy_cp1200 wap150 wap351 wap131 dvg-n5412sp b1165nfw ew-m970a3t ep-101 xp-8500 xp-702 xp-340 xp-620 xp-320 x…
|
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualif…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-12695
|
2024-11-21 14:00 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210897
|
5.3 |
MEDIUM
Network
|
libreoffice fedoraproject opensuse
|
libreoffice fedora leap
|
LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who w…
|
NVD-CWE-Other
|
CVE-2020-12802
|
2024-11-21 14:00 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210898
|
8.8 |
HIGH
Network
|
realtek
|
adsl_router_soc_firmware
|
A security misconfiguration vulnerability exists in the SDK of some Realtek ADSL/PON Modem SoC firmware, which allows attackers using a default password to execute arbitrary commands remotely via the…
|
NVD-CWE-noinfo
|
CVE-2020-12773
|
2024-11-21 14:00 |
2020-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210899
|
7.5 |
HIGH
Network
|
perl netapp fedoraproject opensuse oracle
|
perl snap_creator_framework oncommand_workflow_automation fedora leap communications_eagle_lnp_application_processor sd-wan_edge enterprise_manager_base_platform communication…
|
regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-12723
|
2024-11-21 14:00 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210900
|
5.4 |
MEDIUM
Network
|
pydio
|
cells
|
Pydio Cells 2.0.4 allows any user to upload a profile image to the web application, including standard and shared user roles. These profile pictures can later be accessed directly with the generated …
|
CWE-79
Cross-site Scripting
|
CVE-2020-12849
|
2024-11-21 14:00 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|