|
209431
|
9.6 |
CRITICAL
Network
|
radare fedoraproject
|
radare2 fedora
|
In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger …
|
CWE-78
OS Command
|
CVE-2020-15121
|
2024-11-21 14:04 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209432
|
6.1 |
MEDIUM
Network
|
articatech
|
artica_proxy
|
An issue was discovered in Artica Proxy CE before 4.28.030.418. Reflected XSS exists via these search fields: real time request, System Events, Proxy Events, Proxy Objects, and Firewall objects.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15053
|
2024-11-21 14:04 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209433
|
7.5 |
HIGH
Network
|
articatech
|
artica_proxy
|
An issue was discovered in Artica Proxy CE before 4.28.030.418. SQL Injection exists via the Netmask, Hostname, and Alias fields.
|
CWE-89
SQL Injection
|
CVE-2020-15052
|
2024-11-21 14:04 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209434
|
9.3 |
CRITICAL
Network
|
codecov
|
codecov
|
In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the codecov-node library are unlikely to be aware of this, so they might unwittingly …
|
CWE-78
OS Command
|
CVE-2020-15123
|
2024-11-21 14:04 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209435
|
5.4 |
MEDIUM
Network
|
torchbox
|
wagtail
|
In Wagtail before versions 2.7.4 and 2.9.3, when a form page type is made available to Wagtail editors through the `wagtail.contrib.forms` app, and the page template is built using Django's standard …
|
CWE-79
Cross-site Scripting
|
CVE-2020-15118
|
2024-11-21 14:04 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209436
|
5.4 |
MEDIUM
Network
|
gofiber
|
fiber
|
In Fiber before version 1.12.6, the filename that is given in c.Attachment() (https://docs.gofiber.io/ctx#attachment) is not escaped, and therefore vulnerable for a CRLF injection attack. I.e. an att…
|
CWE-74
Injection
|
CVE-2020-15111
|
2024-11-21 14:04 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209437
|
7.8 |
HIGH
Local
|
asus
|
screenpad2_upgrade_tool
|
AsusScreenXpertServicec.exe and ScreenXpertUpgradeServiceManager.exe in ScreenPad2_Upgrade_Tool.msi V1.0.3 for ASUS PCs with ScreenPad 1.0 (UX450FDX, UX550GDX and UX550GEX) could lead to unsigned cod…
|
CWE-426
Untrusted Search Path
|
CVE-2020-15009
|
2024-11-21 14:04 |
2020-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209438
|
8.1 |
HIGH
Network
|
jupyterhub
|
kubespawner
|
In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant them access to the default server of other users who have matching usernames. T…
|
CWE-863
Incorrect Authorization
|
CVE-2020-15110
|
2024-11-21 14:04 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209439
|
7.1 |
HIGH
Network
|
glpi-project
|
glpi
|
In glpi before 9.5.1, there is a SQL injection for all usages of "Clone" feature. This has been fixed in 9.5.1.
|
CWE-89
SQL Injection
|
CVE-2020-15108
|
2024-11-21 14:04 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209440
|
5.9 |
MEDIUM
Network
|
gnome debian fedoraproject canonical
|
evolution-data-server debian_linux fedora ubuntu_linux
|
evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS c…
|
CWE-74
Injection
|
CVE-2020-14928
|
2024-11-21 14:04 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|