|
208521
|
7.2 |
HIGH
Network
|
clusterlabs debian
|
pacemaker debian_linux
|
An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tas…
|
NVD-CWE-Other
|
CVE-2020-25654
|
2024-11-21 14:18 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208522
|
5.3 |
MEDIUM
Network
|
redhat
|
wildfly
|
A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-25640
|
2024-11-21 14:18 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208523
|
9.8 |
CRITICAL
Network
|
newsscriptphp
|
news_script_php_pro
|
SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action.
|
CWE-89
SQL Injection
|
CVE-2020-25475
|
2024-11-21 14:18 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208524
|
6.1 |
MEDIUM
Network
|
newsscriptphp
|
news_script_php_pro
|
SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Scripting (XSS) vulnerability via the editor_name parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25474
|
2024-11-21 14:18 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208525
|
6.5 |
MEDIUM
Network
|
newsscriptphp
|
news_script_php_pro
|
SimplePHPscripts News Script PHP Pro 2.3 does not properly set the HttpOnly Flag from Session Cookies.
|
NVD-CWE-Other
|
CVE-2020-25473
|
2024-11-21 14:18 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208526
|
6.5 |
MEDIUM
Network
|
newsscriptphp
|
news_script_php_pro
|
SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows attackers to add new users.
|
CWE-352
Origin Validation Error
|
CVE-2020-25472
|
2024-11-21 14:18 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208527
|
7.5 |
HIGH
Network
|
postgresql debian
|
postgresql debian_linux
|
A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If an interactive psql session uses …
|
-
|
CVE-2020-25696
|
2024-11-21 14:18 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208528
|
3.5 |
LOW
Adjacent
|
redhat
|
advanced_cluster_management_for_kubernetes
|
A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-25688
|
2024-11-21 14:18 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208529
|
8.8 |
HIGH
Adjacent
|
redhat fedoraproject
|
ceph ceph_storage openshift_container_platform fedora
|
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilu…
|
-
|
CVE-2020-25660
|
2024-11-21 14:18 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208530
|
5.5 |
MEDIUM
Local
|
xpdfreader fedoraproject
|
xpdf fedora
|
In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a pr…
|
-
|
CVE-2020-25725
|
2024-11-21 14:18 |
2020-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|