|
208591
|
6.1 |
MEDIUM
Network
|
blubrry
|
subscribe_sidebar
|
The Blubrry subscribe-sidebar (aka Subscribe Sidebar) plugin 1.3.1 for WordPress allows subscribe_sidebar.php&status= reflected XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25033
|
2024-11-21 14:16 |
2020-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208592
|
7.5 |
HIGH
Network
|
flask-cors_project debian opensuse
|
flask-cors debian_linux leap backports_sle
|
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathna…
|
CWE-22
Path Traversal
|
CVE-2020-25032
|
2024-11-21 14:16 |
2020-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208593
|
7.8 |
HIGH
Local
|
canonical
|
checkinstall
|
checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 executable file.
|
CWE-59
Link Following
|
CVE-2020-25031
|
2024-11-21 14:16 |
2020-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208594
|
6.1 |
MEDIUM
Network
|
osticket
|
osticket
|
osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24917
|
2024-11-21 14:16 |
2020-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208595
|
8.8 |
HIGH
Network
|
kleopatra_project fedoraproject opensuse
|
kleopatra fedora leap backports_sle
|
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line o…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2020-24972
|
2024-11-21 14:16 |
2020-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208596
|
5.3 |
MEDIUM
Network
|
premid
|
premid
|
managers/socketManager.ts in PreMiD through 2.1.3 has a locally hosted socketio web server (port 3020) open to all origins, which allows attackers to obtain sensitive Discord user information.
|
CWE-862
Missing Authorization
|
CVE-2020-24928
|
2024-11-21 14:16 |
2020-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208597
|
6.5 |
MEDIUM
Network
|
stiltsoft
|
table_filter_and_charts_for_confluence_server
|
The Table Filter and Charts for Confluence Server app before 5.3.26 (for Atlassian Confluence) allows SSRF via the "Table from CSV" macro (URL parameter).
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-24898
|
2024-11-21 14:16 |
2020-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208598
|
8.9 |
HIGH
Network
|
stiltsoft
|
table_filter_and_charts_for_confluence_server
|
The Table Filter and Charts for Confluence Server app before 5.3.25 (for Atlassian Confluence) allow remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) through the…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24897
|
2024-11-21 14:16 |
2020-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208599
|
9.8 |
CRITICAL
Network
|
mpxj oracle
|
mpxj primavera_unifier
|
MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.
|
CWE-611
XXE
|
CVE-2020-25020
|
2024-11-21 14:16 |
2020-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208600
|
7.5 |
HIGH
Network
|
jitsi
|
meet_electron
|
jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-25019
|
2024-11-21 14:16 |
2020-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|