|
210921
|
6.5 |
MEDIUM
Network
|
idreamsoft
|
icms
|
A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN and can still request normally, all administrators except the initial admin…
|
CWE-352
Origin Validation Error
|
CVE-2020-24739
|
2024-11-21 14:15 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210922
|
5.1 |
MEDIUM
Local
|
twilio
|
authy_2-factor_authentication
|
A race condition in the Twilio Authy 2-Factor Authentication application before 24.3.7 for Android allows a user to potentially approve/deny an access request prior to unlocking the application with …
|
CWE-362
Race Condition
|
CVE-2020-24655
|
2024-11-21 14:15 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210923
|
7.5 |
HIGH
Network
|
octopus
|
octopus_deploy
|
In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure steps and sets the step's execution location to r…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-24566
|
2024-11-21 14:15 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210924
|
7.5 |
HIGH
Network
|
gnu fedoraproject opensuse canonical
|
gnutls fedora leap ubuntu_linux
|
An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a no_renegotiation alert is sent with unexpected timing, and then an invalid se…
|
CWE-787 CWE-476
Out-of-bounds Write NULL Pointer Dereference
|
CVE-2020-24659
|
2024-11-21 14:15 |
2020-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210925
|
3.3 |
LOW
Local
|
kde canonical debian opensuse fedoraproject
|
ark ubuntu_linux debian_linux leap fedora
|
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
|
CWE-59
Link Following
|
CVE-2020-24654
|
2024-11-21 14:15 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210926
|
6.1 |
MEDIUM
Network
|
igniterealtime
|
openfire
|
A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via the GET request "searc…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24604
|
2024-11-21 14:15 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210927
|
6.1 |
MEDIUM
Network
|
igniterealtime
|
openfire
|
Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious URL via the vulnerable GET parameter searchName", "searchValu…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24602
|
2024-11-21 14:15 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210928
|
6.1 |
MEDIUM
Network
|
igniterealtime
|
openfire
|
In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST parameter searchName", "alias" in the import certi…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24601
|
2024-11-21 14:15 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210929
|
7.5 |
HIGH
Network
|
djangoproject canonical fedoraproject oracle
|
django ubuntu_linux fedora zfs_storage_appliance_kit
|
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's st…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-24584
|
2024-11-21 14:15 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210930
|
7.5 |
HIGH
Network
|
djangoproject canonical fedoraproject oracle
|
django ubuntu_linux fedora zfs_storage_appliance_kit
|
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level d…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-24583
|
2024-11-21 14:15 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|