|
196261
|
8.8 |
HIGH
Network
|
testlink
|
testlink
|
An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. This allows an a…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-8639
|
2024-11-21 14:39 |
2020-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196262
|
9.8 |
CRITICAL
Network
|
testlink
|
testlink
|
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency parameter.
|
CWE-89
SQL Injection
|
CVE-2020-8638
|
2024-11-21 14:39 |
2020-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196263
|
9.8 |
CRITICAL
Network
|
testlink
|
testlink
|
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter.
|
CWE-89
SQL Injection
|
CVE-2020-8637
|
2024-11-21 14:39 |
2020-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196264
|
8.0 |
HIGH
Adjacent
|
huawei
|
smartax_ma5600t_firmware smartax_ma5800_firmware smartax_ea5800_firmware
|
There is a buffer overflow vulnerability in some Huawei products. The vulnerability can be exploited by an attacker to perform remote code execution on the affected products when the affected product…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-9067
|
2024-11-21 14:39 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196265
|
7.8 |
HIGH
Local
|
linux fedoraproject canonical netapp
|
linux_kernel fedora ubuntu_linux cloud_backup steelstore_cloud_integrated_storage solidfire hci_management_node a700s_firmware 8300_firmware 8700_firmware a400_firmware<…
|
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel …
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-8835
|
2024-11-21 14:39 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196266
|
6.1 |
MEDIUM
Network
|
tiki
|
tikiwiki_cms\/groupware
|
There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-Wiki CMS all versions through 20.0 allows maliciou…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8966
|
2024-11-21 14:39 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196267
|
5.4 |
MEDIUM
Network
|
versiant
|
lynx_customer_service_portal
|
Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to insert malicious JavaScript that is stor…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9055
|
2024-11-21 14:39 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196268
|
4.3 |
MEDIUM
Network
|
kubernetes fedoraproject
|
kubernetes fedora
|
The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-8552
|
2024-11-21 14:39 |
2020-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196269
|
6.5 |
MEDIUM
Adjacent
|
kubernetes fedoraproject
|
kubernetes fedora
|
The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-8551
|
2024-11-21 14:39 |
2020-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196270
|
7.8 |
HIGH
Local
|
huawei
|
oxfordp-an10b_firmware
|
Huawei smartphones OxfordP-AN10B with versions earlier than 10.0.1.169(C00E166R4P1) have an improper authentication vulnerability. The Application doesn't perform proper authentication when user perf…
|
CWE-287
Improper Authentication
|
CVE-2020-9066
|
2024-11-21 14:39 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|