|
208171
|
7.5 |
HIGH
Network
|
misp
|
misp
|
MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-28043
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208172
|
5.3 |
MEDIUM
Network
|
servicestack
|
servicestack
|
ServiceStack before 5.9.2 mishandles JWT signature verification unless an application has a custom ValidateToken function that establishes a valid minimum length for a signature.
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-28042
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208173
|
4.3 |
MEDIUM
Network
|
wordpress debian canonical
|
wordpress debian_linux ubuntu_linux
|
WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.
|
CWE-352
Origin Validation Error
|
CVE-2020-28040
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208174
|
9.1 |
CRITICAL
Network
|
wordpress debian canonical
|
wordpress debian_linux ubuntu_linux
|
is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.
|
NVD-CWE-noinfo
|
CVE-2020-28039
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208175
|
7.8 |
HIGH
Local
|
pax
|
prolinos
|
An unsigned-library issue was discovered in ProlinOS through 2.4.161.8859R. This OS requires installed applications and all system binaries to be signed either by the manufacturer or by the Point Of …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-28045
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208176
|
6.5 |
MEDIUM
Network
|
netgear
|
nighthawk_r7000_firmware
|
The SIP ALG implementation on NETGEAR Nighthawk R7000 1.0.9.64_10.2.64 devices allows remote attackers to communicate with arbitrary TCP and UDP services on a victim's intranet machine, if the victim…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-28041
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208177
|
6.1 |
MEDIUM
Network
|
wordpress fedoraproject debian
|
wordpress fedora debian_linux
|
WordPress before 5.5.2 allows stored XSS via post slugs.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28038
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208178
|
9.8 |
CRITICAL
Network
|
wordpress fedoraproject debian
|
wordpress fedora debian_linux
|
is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, lea…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2020-28037
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208179
|
9.8 |
CRITICAL
Network
|
wordpress fedoraproject debian
|
wordpress fedora debian_linux
|
wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.
|
CWE-862
Missing Authorization
|
CVE-2020-28036
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208180
|
9.8 |
CRITICAL
Network
|
wordpress fedoraproject debian
|
wordpress fedora debian_linux
|
WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.
|
NVD-CWE-noinfo
|
CVE-2020-28035
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|