|
198071
|
8.8 |
HIGH
Network
|
codesnippets
|
code_snippets
|
The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.
|
CWE-352
Origin Validation Error
|
CVE-2020-8417
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198072
|
5.5 |
MEDIUM
Local
|
python
|
python
|
In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-8315
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198073
|
8.8 |
HIGH
Network
|
uclouvain debian
|
openjpeg debian_linux
|
opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-8112
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198074
|
9.8 |
CRITICAL
Network
|
prosody debian
|
mod_auth_ldap2 mod_auth_ldap debian_linux
|
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only fu…
|
CWE-863
Incorrect Authorization
|
CVE-2020-8086
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198075
|
5.4 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue. Any user can modify…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7934
|
2024-11-21 14:38 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198076
|
8.8 |
HIGH
Network
|
super_file_explorer_project
|
super_file_explorer
|
An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the r…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-7998
|
2024-11-21 14:38 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198077
|
6.1 |
MEDIUM
Network
|
asus
|
rt-ac66u_firmware
|
ASUS WRT-AC66U 3 RT 3.0.0.4.372_67 devices allow XSS via the Client Name field to the Parental Control feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7997
|
2024-11-21 14:38 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198078
|
6.1 |
MEDIUM
Network
|
typo3
|
typo3
|
svg.swf in TYPO3 6.2.0 to 6.2.38 ELTS and 7.0.0 to 7.1.0 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system. This may be at a contrib/…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8091
|
2024-11-21 14:38 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198079
|
4.8 |
MEDIUM
Network
|
a1
|
wlan_box_adb_vv2220_firmware
|
The Username field in the Storage Service settings of A1 WLAN Box ADB VV2220v2 devices allows stored XSS (after a successful Administrator login).
|
CWE-79
Cross-site Scripting
|
CVE-2020-8090
|
2024-11-21 14:38 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198080
|
9.8 |
CRITICAL
Network
|
usebb
|
usebb
|
panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password hashes, which mishandles hashes that begin with 0e followed by exclusively numeric…
|
NVD-CWE-noinfo
|
CVE-2020-8088
|
2024-11-21 14:38 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|