|
210421
|
7.8 |
HIGH
Local
|
nakivo
|
backup_\&_replication_director
|
Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access the Nakivo Director web interface and gain root privileges. This occurs because …
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-15850
|
2024-11-21 14:06 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210422
|
6.1 |
MEDIUM
Network
|
joplin_project
|
joplin
|
An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15930
|
2024-11-21 14:06 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210423
|
5.3 |
MEDIUM
Network
|
liferay
|
dxp liferay_portal
|
In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs.
|
NVD-CWE-noinfo
|
CVE-2020-15840
|
2024-11-21 14:06 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210424
|
7.2 |
HIGH
Network
|
telmat
|
accesslog_firmware educ\@box_firmware git\@box_firmware
|
The ping page of the administration panel in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via authenticated code injection over the network.
|
CWE-78
OS Command
|
CVE-2020-16148
|
2024-11-21 14:06 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210425
|
9.8 |
CRITICAL
Network
|
telmat
|
accesslog_firmware educ\@box_firmware git\@box_firmware
|
The login page in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via Unauthenticated code injection over the network.
|
CWE-78
OS Command
|
CVE-2020-16147
|
2024-11-21 14:06 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210426
|
6.5 |
MEDIUM
Network
|
liferay
|
liferay_portal digital_experience_platform
|
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-15839
|
2024-11-21 14:06 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210427
|
7.8 |
HIGH
Local
|
advantech
|
webaccess
|
WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, which may allow code execution with system privileges.
|
-
|
CVE-2020-16202
|
2024-11-21 14:06 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210428
|
4.3 |
MEDIUM
Network
|
google debian opensuse fedoraproject
|
chrome debian_linux leap backports_sle fedora
|
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive informa…
|
NVD-CWE-noinfo
|
CVE-2020-15966
|
2024-11-21 14:06 |
2020-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210429
|
8.8 |
HIGH
Network
|
google debian opensuse fedoraproject
|
chrome debian_linux leap fedora backports_sle
|
Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
|
CWE-843
Type Confusion
|
CVE-2020-15965
|
2024-11-21 14:06 |
2020-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210430
|
8.8 |
HIGH
Network
|
google opensuse fedoraproject debian
|
chrome leap backports_sle fedora debian_linux
|
Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-20 CWE-787 CWE-476
Improper Input Validation Out-of-bounds Write NULL Pointer Dereference
|
CVE-2020-15964
|
2024-11-21 14:06 |
2020-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|