|
207961
|
6.5 |
MEDIUM
Network
|
asterisk sangoma fedoraproject debian
|
certified_asterisk asterisk fedora debian_linux
|
An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1 and Certified Asterisk before 16.8-cert5. If Asterisk is challenge…
|
CWE-674
Uncontrolled Recursion
|
CVE-2020-28242
|
2024-11-21 14:22 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207962
|
8.8 |
HIGH
Network
|
web-audimex
|
audimexee
|
SQL Injection vulnerability in "Documents component" found in AudimexEE version 14.1.0 allows an attacker to execute arbitrary SQL commands via the object_path parameter.
|
CWE-89
SQL Injection
|
CVE-2020-28115
|
2024-11-21 14:22 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207963
|
5.4 |
MEDIUM
Network
|
web-audimex
|
audimexee
|
AudimexEE before 14.1.1 is vulnerable to Reflected XSS (Cross-Site-Scripting). If the recommended security configuration parameter "unique_error_numbers" is not set, remote attackers can inject arbit…
|
CWE-79
Cross-site Scripting
|
CVE-2020-28047
|
2024-11-21 14:22 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207964
|
9.8 |
CRITICAL
Network
|
git_large_file_storage_project
|
git_large_file_storage
|
Git LFS 2.12.0 allows Remote Code Execution.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-27955
|
2024-11-21 14:22 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207965
|
6.3 |
MEDIUM
Local
|
sddm_project opensuse debian fedoraproject
|
sddm leap debian_linux fedora
|
An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server with…
|
CWE-362
Race Condition
|
CVE-2020-28049
|
2024-11-21 14:22 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207966
|
7.8 |
HIGH
Local
|
pax
|
prolinos
|
An issue was discovered in ProlinOS through 2.4.161.8859R. An attacker with local code execution privileges as a normal user (MAINAPP) can escalate to root privileges by exploiting the setuid install…
|
CWE-269
Improper Privilege Management
|
CVE-2020-28046
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207967
|
6.8 |
MEDIUM
Physics
|
pax
|
prolinos
|
An attacker with physical access to a PAX Point Of Sale device with ProlinOS through 2.4.161.8859R can boot it in management mode, enable the XCB service, and then list, read, create, and overwrite f…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-28044
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207968
|
7.5 |
HIGH
Network
|
misp
|
misp
|
MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-28043
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207969
|
5.3 |
MEDIUM
Network
|
servicestack
|
servicestack
|
ServiceStack before 5.9.2 mishandles JWT signature verification unless an application has a custom ValidateToken function that establishes a valid minimum length for a signature.
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-28042
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207970
|
4.3 |
MEDIUM
Network
|
wordpress debian canonical
|
wordpress debian_linux ubuntu_linux
|
WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.
|
CWE-352
Origin Validation Error
|
CVE-2020-28040
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|