|
208321
|
9.6 |
CRITICAL
Network
|
leanote
|
leanote
|
Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This leads to remote code execution because of Node integration.
|
CWE-79
Cross-site Scripting
|
CVE-2020-26158
|
2024-11-21 14:19 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208322
|
9.6 |
CRITICAL
Network
|
leanote
|
leanote
|
Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code execution because of Node integration.
|
CWE-79
Cross-site Scripting
|
CVE-2020-26157
|
2024-11-21 14:19 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208323
|
9.8 |
CRITICAL
Network
|
libproxy_project fedoraproject debian opensuse
|
libproxy fedora debian_linux leap
|
url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-26154
|
2024-11-21 14:19 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208324
|
7.5 |
HIGH
Network
|
logaritmo
|
aware_callmanager
|
info.php in Logaritmo Aware CallManager 2012 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2020-26150
|
2024-11-21 14:19 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208325
|
7.5 |
HIGH
Network
|
linuxfoundation
|
nats.deno nats.js nats.ws
|
NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-26149
|
2024-11-21 14:19 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208326
|
7.5 |
HIGH
Network
|
md4c_project
|
md4c
|
md_push_block_bytes in md4c.c in md4c 0.4.5 allows attackers to trigger use of uninitialized memory, and cause a denial of service (e.g., assertion failure) via a malformed Markdown document.
|
CWE-908
Use of Uninitialized Resource
|
CVE-2020-26148
|
2024-11-21 14:19 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208327
|
6.5 |
MEDIUM
Network
|
python canonical debian oracle
|
urllib3 ubuntu_linux debian_linux zfs_storage_appliance_kit communications_cloud_native_core_network_function_cloud_native_environment
|
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: th…
|
CWE-74
Injection
|
CVE-2020-26137
|
2024-11-21 14:19 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208328
|
6.1 |
MEDIUM
Network
|
hoosk
|
hoosk
|
An issue was discovered in Hoosk CMS v1.8.0. There is a XSS vulnerability in install/index.php
|
CWE-79
Cross-site Scripting
|
CVE-2020-26043
|
2024-11-21 14:19 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208329
|
9.8 |
CRITICAL
Network
|
hoosk
|
hoosk
|
An issue was discovered in Hoosk CMS v1.8.0. There is a SQL injection vulnerability in install/index.php
|
CWE-89
SQL Injection
|
CVE-2020-26042
|
2024-11-21 14:19 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208330
|
9.8 |
CRITICAL
Network
|
hoosk
|
hoosk
|
An issue was discovered in Hoosk CmS v1.8.0. There is an Remote Code Execution vulnerability in install/index.php
|
NVD-CWE-noinfo
|
CVE-2020-26041
|
2024-11-21 14:19 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|