|
209521
|
8.8 |
HIGH
Network
|
dolibarr
|
dolibarr
|
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-14209
|
2024-11-21 14:02 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209522
|
5.9 |
MEDIUM
Network
|
apache netapp
|
cassandra oncommand_insight
|
In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to m…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-13946
|
2024-11-21 14:02 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209523
|
7.5 |
HIGH
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affecte…
|
NVD-CWE-noinfo
|
CVE-2020-14178
|
2024-11-21 14:02 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209524
|
8.1 |
HIGH
Network
|
mitel
|
micollab
|
The SAS portal of Mitel MiCollab before 9.1.3 could allow an attacker to access user data by performing a header injection in HTTP responses, due to the improper handling of input parameters. A succe…
|
CWE-74
Injection
|
CVE-2020-13863
|
2024-11-21 14:02 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209525
|
6.1 |
MEDIUM
Network
|
codiad
|
codiad
|
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and later. The vulnerability occurs because of improper sanitization of the folder's na…
|
CWE-79
Cross-site Scripting
|
CVE-2020-14042
|
2024-11-21 14:02 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209526
|
7.2 |
HIGH
Network
|
codiad
|
codiad
|
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 and later. A user with admin privileges could use the plugin install feature to…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-14044
|
2024-11-21 14:02 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209527
|
8.8 |
HIGH
Network
|
codiad
|
codiad
|
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to download a plugin from the marketplace is only availab…
|
CWE-352
Origin Validation Error
|
CVE-2020-14043
|
2024-11-21 14:02 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209528
|
6.5 |
MEDIUM
Network
|
dolibarr
|
dolibarr
|
Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/document.php in which "disabled" is changed to "enabled" …
|
NVD-CWE-noinfo
|
CVE-2020-14201
|
2024-11-21 14:02 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209529
|
7.5 |
HIGH
Network
|
zulip
|
zulip_server
|
Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations.
|
CWE-269
Improper Privilege Management
|
CVE-2020-14215
|
2024-11-21 14:02 |
2020-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209530
|
5.4 |
MEDIUM
Network
|
zulip
|
zulip_server
|
Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link.
|
CWE-269
Improper Privilege Management
|
CVE-2020-14194
|
2024-11-21 14:02 |
2020-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|