|
208201
|
6.1 |
MEDIUM
Network
|
tt-rss
|
tiny_tiny_rss
|
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25789
|
2024-11-21 14:18 |
2020-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208202
|
8.1 |
HIGH
Network
|
tt-rss
|
tiny_tiny_rss
|
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. imgproxy in plugins/af_proxy_http/init.php mishandles $_REQUEST["url"] in an error message.
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2020-25788
|
2024-11-21 14:18 |
2020-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208203
|
9.8 |
CRITICAL
Network
|
tt-rss
|
tiny_tiny_rss
|
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting them.
|
CWE-20
Improper Input Validation
|
CVE-2020-25787
|
2024-11-21 14:18 |
2020-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208204
|
6.1 |
MEDIUM
Network
|
dlink
|
dir-803_firmware dir-816l_firmware dir-645_firmware dir-815_firmware dir-860l_firmware dir-865l_firmware
|
webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25786
|
2024-11-21 14:18 |
2020-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208205
|
5.3 |
MEDIUM
Network
|
redhat quarkus
|
resteasy quarkus
|
A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentially sensitive information when the server got WebApplicatio…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-25633
|
2024-11-21 14:18 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208206
|
7.5 |
HIGH
Network
|
misp
|
misp
|
An issue was discovered in MISP before 2.4.132. It can perform an unwanted action because of a POST operation on a form that is not linked to the login page.
|
NVD-CWE-noinfo
|
CVE-2020-25766
|
2024-11-21 14:18 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208207
|
9.8 |
CRITICAL
Network
|
cesanta
|
mongoose
|
A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of bounds checking. A crafted HTTP header can exploit this bug. NOTE: a committer has …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-25756
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208208
|
8.8 |
HIGH
Network
|
corephp
|
pago_commerce
|
The paGO Commerce plugin 2.5.9.0 for Joomla! allows SQL Injection via the administrator/index.php?option=com_pago&view=comments filter_published parameter.
|
CWE-89
SQL Injection
|
CVE-2020-25751
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208209
|
7.5 |
HIGH
Network
|
dotplant
|
dotplant2
|
An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the checkResult function. The user input ($_POST['xml']…
|
CWE-611
XXE
|
CVE-2020-25750
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208210
|
8.1 |
HIGH
Network
|
safervpn
|
safervpn
|
SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could cause a denial of service (DoS) condition, because a symlink from %LOCALAPPDATA…
|
CWE-59
Link Following
|
CVE-2020-25744
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|