|
210791
|
3.8 |
LOW
Network
|
gilacms
|
gila_cms
|
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal.
|
CWE-89
SQL Injection
|
CVE-2020-26625
|
2024-11-21 14:20 |
2024-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210792
|
3.8 |
LOW
Network
|
gilacms
|
gila_cms
|
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.
|
CWE-89
SQL Injection
|
CVE-2020-26624
|
2024-11-21 14:20 |
2024-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210793
|
3.8 |
LOW
Network
|
gilacms
|
gila_cms
|
SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the lo…
|
CWE-89
SQL Injection
|
CVE-2020-26623
|
2024-11-21 14:20 |
2024-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210794
|
7.5 |
HIGH
Network
|
ethernut
|
nut\/os
|
An issue was discovered in Ethernut Nut/OS 5.1. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attac…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-27213
|
2024-11-21 14:20 |
2023-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210795
|
5.5 |
MEDIUM
Local
|
artifex
|
mupdf
|
A memory leak issue discovered in /pdf/pdf-font-add.c in Artifex Software MuPDF 1.17.0 allows attackers to obtain sensitive information.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-26683
|
2024-11-21 14:20 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210796
|
7.5 |
HIGH
Network
|
realtek
|
rtl8812au_firmware
|
An issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of service.
|
NVD-CWE-noinfo
|
CVE-2020-26652
|
2024-11-21 14:20 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210797
|
7.5 |
HIGH
Network
|
py-xml_project
|
py-xml
|
py-xml v1.0 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.
|
CWE-611
XXE
|
CVE-2020-26709
|
2024-11-21 14:20 |
2023-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210798
|
7.5 |
HIGH
Network
|
requests-xml_project
|
requests-xml
|
requests-xml v0.2.3 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.
|
CWE-611
XXE
|
CVE-2020-26708
|
2024-11-21 14:20 |
2023-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210799
|
7.2 |
HIGH
Network
|
oauth2-server_project
|
oauth2-server
|
In oauth2-server (aka node-oauth2-server) through 3.1.1, the value of the redirect_uri parameter received during the authorization and token request is checked against an incorrect URI pattern ("[a-z…
|
CWE-601
Open Redirect
|
CVE-2020-26938
|
2024-11-21 14:20 |
2022-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210800
|
6.1 |
MEDIUM
Network
|
apifest
|
oauth_2.0_server
|
ApiFest OAuth 2.0 Server 0.3.1 does not validate the redirect URI in accordance with RFC 6749 and is susceptible to an open redirector attack. Specifically, it directly sends an authorization code to…
|
CWE-601
Open Redirect
|
CVE-2020-26877
|
2024-11-21 14:20 |
2022-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|