|
210961
|
6.1 |
MEDIUM
Network
|
rcos
|
submitty
|
Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.
|
CWE-601
Open Redirect
|
CVE-2020-13121
|
2024-11-21 14:00 |
2020-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210962
|
9.8 |
CRITICAL
Network
|
mikrotik-router-monitoring-system_project
|
mikrotik-router-monitoring-system
|
An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter community.
|
CWE-89
SQL Injection
|
CVE-2020-13118
|
2024-11-21 14:00 |
2020-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210963
|
7.5 |
HIGH
Network
|
naviserver_project
|
naviserver
|
NaviServer 4.99.4 to 4.99.19 allows denial of service due to the nsd/driver.c ChunkedDecode function not properly validating the length of a chunk. A remote attacker can craft a chunked-transfer requ…
|
CWE-20 CWE-787
Improper Input Validation Out-of-bounds Write
|
CVE-2020-13111
|
2024-11-21 14:00 |
2020-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210964
|
7.8 |
HIGH
Local
|
kerberos_project
|
kerberos
|
The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of the kerberos_sspi LoadLibrary() method, because o…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-13110
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210965
|
9.8 |
CRITICAL
Network
|
seta
|
morita_shogi_64
|
Morita Shogi 64 through 2020-05-02 for Nintendo 64 devices allows remote attackers to execute arbitrary code via crafted packet data to the built-in modem because 0x800b3e94 (aka the IF subcommand to…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13109
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210966
|
5.3 |
MEDIUM
Network
|
ispyconnect
|
agent_dvr
|
iSpyConnect.com Agent DVR before 2.7.1.0 allows directory traversal.
|
CWE-22
Path Traversal
|
CVE-2020-13093
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210967
|
9.8 |
CRITICAL
Network
|
scikit-learn
|
scikit-learn
|
scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to the joblib.load() function, if __reduce__ makes an os.system call. NOTE: third …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-13092
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210968
|
9.8 |
CRITICAL
Network
|
numfocus
|
pandas
|
pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-13091
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210969
|
5.5 |
MEDIUM
Local
|
yaws
|
yaws
|
yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if running on an Erlang/OTP virtual machine with a version less than…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-12872
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210970
|
9.8 |
CRITICAL
Network
|
misp
|
misp-maltego
|
MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across users in a remote-transform use case.
|
NVD-CWE-noinfo
|
CVE-2020-12889
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|