|
209161
|
6.1 |
MEDIUM
Network
|
nexos_project
|
nexos
|
The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15364
|
2024-11-21 14:05 |
2020-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209162
|
9.8 |
CRITICAL
Network
|
nexos_project
|
nexos
|
The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2020-15363
|
2024-11-21 14:05 |
2020-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209163
|
7.8 |
HIGH
Local
|
docker
|
docker_desktop
|
com.docker.vmnetd in Docker Desktop 2.3.0.3 allows privilege escalation because of a lack of client verification.
|
CWE-862
Missing Authorization
|
CVE-2020-15360
|
2024-11-21 14:05 |
2020-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209164
|
5.5 |
MEDIUM
Local
|
sqlite canonical apple oracle siemens
|
sqlite ubuntu_linux iphone_os watchos icloud tvos ipados macos outside_in_technology hyperion_infrastructure_technology enterprise_manager_ops_center communications_n…
|
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-15358
|
2024-11-21 14:05 |
2020-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209165
|
7.8 |
HIGH
Local
|
idrive
|
idrive
|
IDrive before 6.7.3.19 on Windows installs by default to %PROGRAMFILES(X86)%\IDriveWindows with weak folder permissions granting any user modify permission (i.e., NT AUTHORITY\Authenticated Users:(OI…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-15351
|
2024-11-21 14:05 |
2020-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209166
|
7.5 |
HIGH
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /cnr requests.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-15336
|
2024-11-21 14:05 |
2020-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209167
|
7.5 |
HIGH
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /registerCpe requests.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-15335
|
2024-11-21 14:05 |
2020-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209168
|
9.8 |
CRITICAL
Network
|
zyxel
|
cloud_cnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows use of live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids= for eval injection of Python code.
|
CWE-94
Code Injection
|
CVE-2020-15348
|
2024-11-21 14:05 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209169
|
7.2 |
HIGH
Network
|
turnkeylinux
|
support_incident_tracker
|
Support Incident Tracker (aka SiT! or SiTracker) 3.67 p2 allows post-authentication SQL injection via the site_edit.php typeid or site parameter, the search_incidents_advanced.php search_title parame…
|
CWE-89
SQL Injection
|
CVE-2020-15308
|
2024-11-21 14:05 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209170
|
5.5 |
MEDIUM
Local
|
openexr fedoraproject opensuse debian canonical
|
openexr fedora leap debian_linux ubuntu_linux
|
An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-15306
|
2024-11-21 14:05 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|