|
208211
|
6.1 |
MEDIUM
Network
|
webtareas_project
|
webtareas
|
webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement.php, administration/departments.php, administration/locations.php, expenses/cl…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25735
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208212
|
5.3 |
MEDIUM
Network
|
webtareas_project
|
webtareas
|
webTareas through 2.1 allows files/Default/ Directory Listing.
|
CWE-22
Path Traversal
|
CVE-2020-25734
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208213
|
7.5 |
HIGH
Network
|
webtareas_project
|
webtareas
|
webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-25733
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208214
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25729
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208215
|
9.8 |
CRITICAL
Network
|
sqreen
|
python_mini_racer
|
A heap overflow in Sqreen PyMiniRacer (aka Python Mini Racer) before 0.3.0 allows remote attackers to potentially exploit heap corruption.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-25489
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208216
|
8.8 |
HIGH
Network
|
alfresco
|
reset_password
|
The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2020-25728
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208217
|
7.5 |
HIGH
Network
|
flexsolution
|
reset_password
|
The Reset Password add-on before 1.2.0 for Alfresco suffers from CMIS-SQL Injection, which allows a malicious user to inject a query within the email input field.
|
CWE-89
SQL Injection
|
CVE-2020-25727
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208218
|
7.3 |
HIGH
Network
|
sqreen
|
php_microagent
|
Lack of cryptographic signature verification in the Sqreen PHP agent daemon before 1.16.0 makes it easier for remote attackers to inject rules for execution inside the virtual machine.
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-25490
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208219
|
9.8 |
CRITICAL
Network
|
xmlquery_project
|
xmlquery
|
xmlquery before 1.3.1 lacks a check for whether a LoadURL response is in the XML format, which allows attackers to cause a denial of service (SIGSEGV) at xmlquery.(*Node).InnerText or possibly have u…
|
CWE-119 CWE-20
Incorrect Access of Indexable Resource ('Range Error') Improper Input Validation
|
CVE-2020-25614
|
2024-11-21 14:18 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208220
|
7.8 |
HIGH
Local
|
gnuplot_project
|
gnuplot
|
gnuplot 5.5 is affected by double free when executing print_set_output. This may result in context-dependent arbitrary code execution.
|
CWE-415
Double Free
|
CVE-2020-25559
|
2024-11-21 14:18 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|