|
209011
|
8.8 |
HIGH
Network
|
carson-saint
|
saint_security_suite
|
An SQL injection vulnerability in the Assets component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, authenticated attacker to gain unauthorized access to the database.
|
CWE-89
SQL Injection
|
CVE-2020-16276
|
2024-11-21 14:07 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209012
|
6.1 |
MEDIUM
Network
|
carson-saint
|
saint_security_suite
|
A cross-site scripting (XSS) vulnerability in the Credential Manager component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-16275
|
2024-11-21 14:07 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209013
|
5.8 |
MEDIUM
Network
|
prometheus
|
blackbox_exporter
|
Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerab…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-16248
|
2024-11-21 14:07 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209014
|
8.8 |
HIGH
Network
|
sophos
|
xg_firewall_firmware
|
Two OS command injection vulnerabilities in the User Portal of Sophos XG Firewall through 2020-08-05 potentially allow an authenticated attacker to remotely execute arbitrary code.
|
CWE-78
OS Command
|
CVE-2020-17352
|
2024-11-21 14:07 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209015
|
7.5 |
HIGH
Network
|
golang opensuse debian fedoraproject
|
go leap debian_linux fedora
|
Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-16845
|
2024-11-21 14:07 |
2020-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209016
|
7.4 |
HIGH
Network
|
nlnetlabs
|
routinator
|
An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent routing systems by…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-17366
|
2024-11-21 14:07 |
2020-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209017
|
6.1 |
MEDIUM
Network
|
chartkick_project
|
chartkick
|
The Chartkick gem through 3.3.2 for Ruby allows Cascading Style Sheets (CSS) Injection (without attribute).
|
CWE-74
Injection
|
CVE-2020-16254
|
2024-11-21 14:07 |
2020-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209018
|
6.1 |
MEDIUM
Network
|
usvn
|
user-friendly_svn
|
USVN (aka User-friendly SVN) before 1.0.9 allows XSS via SVN logs.
|
CWE-79
Cross-site Scripting
|
CVE-2020-17364
|
2024-11-21 14:07 |
2020-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209019
|
9.8 |
CRITICAL
Network
|
lilypond fedoraproject debian opensuse
|
lilypond fedora debian_linux leap backports_sle
|
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous …
|
NVD-CWE-noinfo
|
CVE-2020-17353
|
2024-11-21 14:07 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209020
|
8.1 |
HIGH
Network
|
pghero_project
|
pghero
|
The PgHero gem through 2.6.0 for Ruby allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-16253
|
2024-11-21 14:07 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|