|
208751
|
5.3 |
MEDIUM
Network
|
umanni
|
human_resources
|
Umanni RH 1.0 has a user enumeration vulnerability. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabli…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-24008
|
2024-11-21 14:14 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208752
|
9.8 |
CRITICAL
Network
|
umanni
|
human_resources
|
Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-24007
|
2024-11-21 14:14 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208753
|
6.1 |
MEDIUM
Network
|
rss_feed_widget_project
|
rss_feed_widget
|
Fahad Mahmood RSS Feed Widget Plugin v2.7.9 and lower does not sanitize the value of the "t" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerabilit…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24314
|
2024-11-21 14:14 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208754
|
6.1 |
MEDIUM
Network
|
etoilewebdesign
|
ultimate_appointment_booking_\&_scheduling
|
Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET parameter before echoing it back out inside an in…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24313
|
2024-11-21 14:14 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208755
|
7.5 |
HIGH
Network
|
webdesi9
|
file_manager
|
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and do…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2020-24312
|
2024-11-21 14:14 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208756
|
5.5 |
MEDIUM
Local
|
nasm
|
netwide_assembler
|
In Netwide Assembler (NASM) 2.15rc10, SEGV can be triggered in tok_text in asm/preproc.c by accessing READ memory.
|
NVD-CWE-noinfo
|
CVE-2020-24242
|
2024-11-21 14:14 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208757
|
5.5 |
MEDIUM
Local
|
nasm
|
netwide_assembler
|
In Netwide Assembler (NASM) 2.15rc10, there is heap use-after-free in saa_wbytes in nasmlib/saa.c.
|
CWE-416
Use After Free
|
CVE-2020-24241
|
2024-11-21 14:14 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208758
|
5.5 |
MEDIUM
Local
|
gnu
|
bison
|
GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is a risk only if Bison is used with untrusted input,…
|
CWE-416
Use After Free
|
CVE-2020-24240
|
2024-11-21 14:14 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208759
|
8.8 |
HIGH
Network
|
ethz
|
minetime
|
MineTime through 1.8.5 allows arbitrary command execution via the notes field in a meeting. Could lead to RCE via meeting invite.
|
CWE-74
Injection
|
CVE-2020-24364
|
2024-11-21 14:14 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208760
|
10.0 |
CRITICAL
Network
|
gvectors
|
wpdiscuz
|
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via th…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-24186
|
2024-11-21 14:14 |
2020-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|