|
209261
|
6.1 |
MEDIUM
Network
|
igniterealtime
|
openfire
|
A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via the GET request "searc…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24604
|
2024-11-21 14:15 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209262
|
6.1 |
MEDIUM
Network
|
igniterealtime
|
openfire
|
Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious URL via the vulnerable GET parameter searchName", "searchValu…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24602
|
2024-11-21 14:15 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209263
|
6.1 |
MEDIUM
Network
|
igniterealtime
|
openfire
|
In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST parameter searchName", "alias" in the import certi…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24601
|
2024-11-21 14:15 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209264
|
7.5 |
HIGH
Network
|
djangoproject canonical fedoraproject oracle
|
django ubuntu_linux fedora zfs_storage_appliance_kit
|
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's st…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-24584
|
2024-11-21 14:15 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209265
|
7.5 |
HIGH
Network
|
djangoproject canonical fedoraproject oracle
|
django ubuntu_linux fedora zfs_storage_appliance_kit
|
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level d…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-24583
|
2024-11-21 14:15 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209266
|
6.1 |
MEDIUM
Network
|
chamber_dashboard_business_directory_project
|
chamber_dashboard_business_directory
|
The Chamber Dashboard Business Directory plugin 3.2.8 for WordPress allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24699
|
2024-11-21 14:15 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209267
|
9.8 |
CRITICAL
Network
|
scalyr
|
scalyr_agent
|
The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, native Python code is used that lacks a comparison of the hostname to commonName and subjectAltNa…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-24715
|
2024-11-21 14:15 |
2020-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209268
|
9.8 |
CRITICAL
Network
|
scalyr
|
scalyr_agent
|
The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, the openssl binary is called without the -verify_hostname option.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-24714
|
2024-11-21 14:15 |
2020-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209269
|
6.5 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access.
|
NVD-CWE-noinfo
|
CVE-2020-24618
|
2024-11-21 14:15 |
2020-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209270
|
7.8 |
HIGH
Local
|
openzfs
|
openzfs
|
OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by mode 0770 being equivalent to mode 0777.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-24717
|
2024-11-21 14:15 |
2020-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|