|
211361
|
9.1 |
CRITICAL
Network
|
getkirby
|
panel kirby
|
Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.4.5, and Kirby Panel before version 2.5.14 , an editor with full access to the Kirby Panel can upload a PHP .phar file and execute it on t…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-26255
|
2024-11-21 14:19 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211362
|
5.4 |
MEDIUM
Network
|
student_management_system_project_in_php_project
|
student_management_system_project_in_php
|
SourceCodester Student Management System Project in PHP version 1.0 is vulnerable to stored a cross-site scripting (XSS) via the 'add subject' tab.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25955
|
2024-11-21 14:19 |
2020-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211363
|
7.7 |
HIGH
Network
|
omniauth-apple_project
|
omniauth-apple
|
omniauth-apple is the OmniAuth strategy for "Sign In with Apple" (RubyGem omniauth-apple). In omniauth-apple before version 1.0.1 attackers can fake their email address during authentication. This vu…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2020-26254
|
2024-11-21 14:19 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211364
|
5.9 |
MEDIUM
Network
|
getkirby
|
kirby panel
|
Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.3.6, and Kirby Panel before version 2.5.14 there is a vulnerability in which the admin panel may be accessed if hosted on a .dev domain. I…
|
CWE-346
Origin Validation Error
|
CVE-2020-26253
|
2024-11-21 14:19 |
2020-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211365
|
5.5 |
MEDIUM
Local
|
intland
|
codebeamer
|
An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM application to import projects, is parsed by insecurely configured software com…
|
CWE-611
XXE
|
CVE-2020-26513
|
2024-11-21 14:19 |
2020-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211366
|
7.2 |
HIGH
Network
|
inspur
|
nf8480m5_firmware nf8260m5_firmware ns5162m5_firmware ns5488m5_firmware ns5484m5_firmware ns5482m5_firmware nf5280m5_firmware nf5468m5_firmware nf5488m5-d_firmware nf5180m5…
|
Inspur NF5266M5 through 3.21.2 and other server M5 devices allow remote code execution via administrator privileges. The Baseboard Management Controller (BMC) program of INSPUR server is weak in chec…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-26122
|
2024-11-21 14:19 |
2020-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211367
|
8.2 |
HIGH
Network
|
prestashop
|
productcomments
|
In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module.
|
CWE-89
SQL Injection
|
CVE-2020-26248
|
2024-11-21 14:19 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211368
|
6.5 |
MEDIUM
Network
|
pimcore
|
pimcore
|
Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create website settings without having the appropriate permissions.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-26246
|
2024-11-21 14:19 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211369
|
6.8 |
MEDIUM
Network
|
python_openid_connect_project
|
python_openid_connect
|
Python oic is a Python OpenID Connect implementation. In Python oic before version 1.2.1, there are several related cryptographic issues affecting client implementations that use the library. The iss…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-26244
|
2024-11-21 14:19 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211370
|
6.3 |
MEDIUM
Network
|
jupyter
|
oauthenticator
|
OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the deprecated (in jupyterhub 1.2) configuration `Authenticator.whitelist`, which s…
|
CWE-863
Incorrect Authorization
|
CVE-2020-26250
|
2024-11-21 14:19 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|