|
209001
|
6.1 |
MEDIUM
Network
|
themeinprogress
|
nova_lite
|
search.php in the Nova Lite theme before 1.3.9 for WordPress allows Reflected XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-17362
|
2024-11-21 14:07 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209002
|
5.5 |
MEDIUM
Local
|
readytalk
|
avian
|
An issue was discovered in ReadyTalk Avian 1.2.0. The vm::arrayCopy method defined in classpath-common.h returns silently when a negative length is provided (instead of throwing an exception). This c…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-17361
|
2024-11-21 14:07 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209003
|
7.8 |
HIGH
Local
|
readytalk
|
avian
|
An issue was discovered in ReadyTalk Avian 1.2.0. The vm::arrayCopy method defined in classpath-common.h contains multiple boundary checks that are performed to prevent out-of-bounds memory read/writ…
|
CWE-125 CWE-787 CWE-190
Out-of-bounds Read Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2020-17360
|
2024-11-21 14:07 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209004
|
5.3 |
MEDIUM
Network
|
sugarcrm
|
sugarcrm
|
SugarCRM before 10.1.0 (Q3 2020) allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2020-17373
|
2024-11-21 14:07 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209005
|
5.4 |
MEDIUM
Network
|
sugarcrm
|
sugarcrm
|
SugarCRM before 10.1.0 (Q3 2020) allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-17372
|
2024-11-21 14:07 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209006
|
5.4 |
MEDIUM
Network
|
mantisbt
|
mantisbt
|
An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attacker to inject arbitrary HTML into the page by saving it into a text Custom Field…
|
CWE-79
Cross-site Scripting
|
CVE-2020-16266
|
2024-11-21 14:07 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209007
|
9.8 |
CRITICAL
Network
|
firejail_project debian fedoraproject opensuse
|
firejail debian_linux fedora leap
|
Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.
|
CWE-78
OS Command
|
CVE-2020-17368
|
2024-11-21 14:07 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209008
|
7.8 |
HIGH
Local
|
firejail_project debian fedoraproject opensuse
|
firejail debian_linux fedora leap
|
Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.
|
CWE-88
Argument Injection
|
CVE-2020-17367
|
2024-11-21 14:07 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209009
|
6.1 |
MEDIUM
Network
|
carson-saint
|
saint_security_suite
|
A cross-site scripting (XSS) vulnerability in the Permissions component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when the user…
|
CWE-79
Cross-site Scripting
|
CVE-2020-16278
|
2024-11-21 14:07 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209010
|
8.8 |
HIGH
Network
|
carson-saint
|
saint_security_suite
|
An SQL injection vulnerability in the Analytics component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, authenticated attacker to gain unauthorized access to the database.
|
CWE-89
SQL Injection
|
CVE-2020-16277
|
2024-11-21 14:07 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|