|
209831
|
9.8 |
CRITICAL
Network
|
turcom
|
trcwifizone
|
Turcom TRCwifiZone through 2020-08-10 allows authentication bypass by visiting manage/control.php and ignoring 302 Redirect responses.
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2020-17466
|
2024-11-21 14:08 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209832
|
7.8 |
HIGH
Local
|
telegram
|
telegram_desktop
|
Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use of the chat window with a filename that lacks an ex…
|
CWE-863
Incorrect Authorization
|
CVE-2020-17448
|
2024-11-21 14:08 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209833
|
6.1 |
MEDIUM
Network
|
tiny
|
tinymce
|
TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
|
CWE-79
Cross-site Scripting
|
CVE-2020-17480
|
2024-11-21 14:08 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209834
|
9.8 |
CRITICAL
Network
|
json_pattern_validator_project
|
json_pattern_validator
|
jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array.
|
CWE-20
Improper Input Validation
|
CVE-2020-17479
|
2024-11-21 14:08 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209835
|
7.5 |
HIGH
Network
|
p5-crypt-perl_project
|
p5-crypt-perl
|
ECDSA/EC/Point.pm in Crypt::Perl before 0.33 does not properly consider timing attacks against the EC point multiplication algorithm.
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-17478
|
2024-11-21 14:08 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209836
|
6.1 |
MEDIUM
Network
|
mibew
|
messenger
|
Mibew Messenger before 3.2.7 allows XSS via a crafted user name.
|
CWE-79
Cross-site Scripting
|
CVE-2020-17476
|
2024-11-21 14:08 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209837
|
7.2 |
HIGH
Network
|
flatcore
|
flatcore
|
flatCore before 1.5.7 allows upload and execution of a .php file by an admin.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-17452
|
2024-11-21 14:08 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209838
|
4.8 |
MEDIUM
Network
|
flatcore
|
flatcore
|
flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title, page_content, or page_extracontent parameter, or the acp/acp.php?tn=system&sub…
|
CWE-79
Cross-site Scripting
|
CVE-2020-17451
|
2024-11-21 14:08 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209839
|
7.8 |
HIGH
Local
|
microsoft
|
python_extension
|
Visual Studio Code Python Extension Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2020-17163
|
2024-11-21 14:07 |
2023-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209840
|
8.6 |
HIGH
Local
|
lilypond
|
lilypond
|
LilyPond before 2.24 allows attackers to bypass the -dsafe protection mechanism via output-def-lookup or output-def-scope, as demonstrated by dangerous Scheme code in a .ly file that causes arbitrary…
|
CWE-863
Incorrect Authorization
|
CVE-2020-17354
|
2024-11-21 14:07 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|