|
208151
|
8.8 |
HIGH
Network
|
qdpm
|
qdpm
|
qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-26165
|
2024-11-21 14:19 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208152
|
8.7 |
HIGH
Network
|
vega_project
|
vega
|
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega in an npm package. In Vega before version 5.17.3 there is an XSS vulner…
|
-
|
CVE-2020-26296
|
2024-11-21 14:19 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208153
|
6.5 |
MEDIUM
Network
|
uri.js_project
|
uri.js
|
URI.js is a javascript URL mutation library (npm package urijs). In URI.js before version 1.19.4, the hostname can be spoofed by using a backslash (`\`) character followed by an at (`@`) character. I…
|
-
|
CVE-2020-26291
|
2024-11-21 14:19 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208154
|
6.5 |
MEDIUM
Network
|
parseplatform
|
parse-server
|
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. It is an npm package "parse-server". In Parse Server before version 4.5.0, user passwords invol…
|
-
|
CVE-2020-26288
|
2024-11-21 14:19 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208155
|
4.3 |
MEDIUM
Network
|
nokogiri debian
|
nokogiri debian_linux
|
Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Noko…
|
CWE-611
XXE
|
CVE-2020-26247
|
2024-11-21 14:19 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208156
|
8.7 |
HIGH
Network
|
hedgedoc
|
hedgedoc
|
HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an attacker can inject arbitrary `script` tags in HedgeDoc notes using mermaid diagrams. Our co…
|
CWE-79
Cross-site Scripting
|
CVE-2020-26287
|
2024-11-21 14:19 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208157
|
7.5 |
HIGH
Network
|
hedgedoc
|
hedgedoc
|
HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an unauthenticated attacker can upload arbitrary files to the upload storage backend including …
|
-
|
CVE-2020-26286
|
2024-11-21 14:19 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208158
|
9.6 |
CRITICAL
Network
|
linuxfoundation
|
dex
|
Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulnerabilities which impacts users leveraging the SAML connector. The vulnerabilitie…
|
-
|
CVE-2020-26290
|
2024-11-21 14:19 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208159
|
7.5 |
HIGH
Network
|
date-and-time_project
|
date-and-time
|
date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be exploited to to cause a denial of s…
|
-
|
CVE-2020-26289
|
2024-11-21 14:19 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208160
|
5.4 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket.
|
CWE-79
Cross-site Scripting
|
CVE-2020-26035
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|