|
208361
|
4.3 |
MEDIUM
Network
|
pyrocms
|
pyrocms
|
PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/pages/delete/ URI: pages will be deleted.
|
CWE-352
Origin Validation Error
|
CVE-2020-25262
|
2024-11-21 14:17 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208362
|
5.4 |
MEDIUM
Network
|
getsymphony
|
symphony
|
Cross-site scripting (XSS) vulnerabilities in Symphony CMS 3.0.0 allow remote attackers to inject arbitrary web script or HTML to fields['body'] param via events\event.publish_article.php
|
CWE-79
Cross-site Scripting
|
CVE-2020-25343
|
2024-11-21 14:17 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208363
|
5.3 |
MEDIUM
Network
|
pritunl
|
pritunl
|
Pritunl 1.29.2145.25 allows attackers to enumerate valid VPN usernames via a series of /auth/session login attempts. Initially, the server will return error 401. However, if the username is valid, th…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-25200
|
2024-11-21 14:17 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208364
|
4.8 |
MEDIUM
Network
|
mantisbt
|
mantisbt
|
An issue was discovered in MantisBT before 2.24.3. When editing an Issue in a Project where a Custom Field with a crafted Regular Expression property is used, improper escaping of the corresponding f…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25288
|
2024-11-21 14:17 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208365
|
8.8 |
HIGH
Network
|
observium
|
observium
|
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted po…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2020-25149
|
2024-11-21 14:17 |
2020-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208366
|
6.1 |
MEDIUM
Network
|
observium
|
observium
|
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious …
|
CWE-79
Cross-site Scripting
|
CVE-2020-25148
|
2024-11-21 14:17 |
2020-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208367
|
9.8 |
CRITICAL
Network
|
observium
|
observium
|
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL statements in malfo…
|
CWE-89
SQL Injection
|
CVE-2020-25147
|
2024-11-21 14:17 |
2020-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208368
|
6.1 |
MEDIUM
Network
|
observium
|
observium
|
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious …
|
CWE-79
Cross-site Scripting
|
CVE-2020-25146
|
2024-11-21 14:17 |
2020-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208369
|
8.8 |
HIGH
Network
|
observium
|
observium
|
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted po…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2020-25145
|
2024-11-21 14:17 |
2020-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208370
|
8.8 |
HIGH
Network
|
observium
|
observium
|
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted po…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2020-25144
|
2024-11-21 14:17 |
2020-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|