|
198251
|
5.4 |
MEDIUM
Network
|
elementor
|
website_builder
|
The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page. These can be exploited by targeting an authenticated user.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8426
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198252
|
6.5 |
MEDIUM
Network
|
cups_easy_\(purchase_\&_inventory\)_project
|
cups_easy_\(purchase_\&_inventory\)
|
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-8425
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198253
|
8.8 |
HIGH
Network
|
cups_easy_project
|
cups_easy
|
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-8424
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198254
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8421
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198255
|
8.8 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.
|
CWE-352
Origin Validation Error
|
CVE-2020-8420
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198256
|
8.8 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.
|
CWE-352
Origin Validation Error
|
CVE-2020-8419
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198257
|
8.8 |
HIGH
Network
|
codesnippets
|
code_snippets
|
The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.
|
CWE-352
Origin Validation Error
|
CVE-2020-8417
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198258
|
5.5 |
MEDIUM
Local
|
python
|
python
|
In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-8315
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198259
|
8.8 |
HIGH
Network
|
uclouvain debian
|
openjpeg debian_linux
|
opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-8112
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198260
|
9.8 |
CRITICAL
Network
|
prosody debian
|
mod_auth_ldap2 mod_auth_ldap debian_linux
|
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only fu…
|
CWE-863
Incorrect Authorization
|
CVE-2020-8086
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|