|
208341
|
8.8 |
HIGH
Network
|
ilias
|
ilias
|
Remote Code Execution can occur via the external news feed in ILIAS 6.4 because of incorrect parameter sanitization for Magpie RSS data.
|
CWE-88
Argument Injection
|
CVE-2020-25268
|
2024-11-21 14:17 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208342
|
5.4 |
MEDIUM
Network
|
ilias
|
ilias
|
An XSS issue exists in the question-pool file-upload preview feature in ILIAS 6.4.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25267
|
2024-11-21 14:17 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208343
|
9.8 |
CRITICAL
Network
|
moinmo debian
|
moinmoin debian_linux
|
The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use this to achieve re…
|
CWE-22
Path Traversal
|
CVE-2020-25074
|
2024-11-21 14:17 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208344
|
7.8 |
HIGH
Local
|
bbraun
|
onlinesuite_application_package
|
A DLL hijacking vulnerability in the B. Braun OnlineSuite Version AP 3.0 and earlier allows local attackers to execute code on the system as a high privileged user.
|
-
|
CVE-2020-25174
|
2024-11-21 14:17 |
2020-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208345
|
9.8 |
CRITICAL
Network
|
bbraun
|
onlinesuite_application_package
|
A relative path traversal attack in the B. Braun OnlineSuite Version AP 3.0 and earlier allows unauthenticated attackers to upload or download arbitrary files.
|
-
|
CVE-2020-25172
|
2024-11-21 14:17 |
2020-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208346
|
7.8 |
HIGH
Local
|
bbraun
|
onlinesuite_application_package
|
An Excel Macro Injection vulnerability exists in the export feature in the B. Braun OnlineSuite Version AP 3.0 and earlier via multiple input fields that are mishandled in an Excel export.
|
-
|
CVE-2020-25170
|
2024-11-21 14:17 |
2020-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208347
|
7.8 |
HIGH
Local
|
mind
|
imind_server
|
Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chat.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25399
|
2024-11-21 14:17 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208348
|
8.8 |
HIGH
Network
|
mind
|
imind_server
|
CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-25398
|
2024-11-21 14:17 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208349
|
7.5 |
HIGH
Network
|
hashicorp
|
consul
|
HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes. Fixed in 1.7.9 and 1.8.5.
|
NVD-CWE-noinfo
|
CVE-2020-25201
|
2024-11-21 14:17 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208350
|
2.6 |
LOW
Network
|
cyberark
|
privileged_session_manager
|
CyberArk Privileged Session Manager (PSM) 10.9.0.15 allows attackers to discover internal pathnames by reading an error popup message after two hours of idle time.
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-25374
|
2024-11-21 14:17 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|