|
208381
|
7.2 |
HIGH
Network
|
batflat
|
batflat
|
Sruu.pl in Batflat 1.3.6 allows an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Users tab. To exploit this, one must login to the …
|
CWE-94
Code Injection
|
CVE-2020-35734
|
2024-11-21 14:27 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208382
|
7.8 |
HIGH
Local
|
freedesktop
|
dbus
|
A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharin…
|
CWE-416
Use After Free
|
CVE-2020-35512
|
2024-11-21 14:27 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208383
|
7.5 |
HIGH
Network
|
openvswitch debian fedoraproject
|
openvswitch debian_linux fedora
|
A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow i…
|
-
|
CVE-2020-35498
|
2024-11-21 14:27 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208384
|
6.1 |
MEDIUM
Network
|
adminer
|
adminer
|
Adminer through 4.7.8 allows XSS via the history parameter to the default URI.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35572
|
2024-11-21 14:27 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208385
|
8.8 |
HIGH
Network
|
librenms
|
librenms
|
A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNMS before 21.1.0 allows remote authenticated attackers to execute arbitrary SQL …
|
CWE-89
SQL Injection
|
CVE-2020-35700
|
2024-11-21 14:27 |
2021-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208386
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-35667
|
2024-11-21 14:27 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208387
|
5.4 |
MEDIUM
Network
|
solarwinds
|
serv-u
|
SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35482
|
2024-11-21 14:27 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208388
|
9.8 |
CRITICAL
Network
|
solarwinds
|
serv-u
|
SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.
|
NVD-CWE-Other
|
CVE-2020-35481
|
2024-11-21 14:27 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208389
|
6.5 |
MEDIUM
Network
|
digium
|
asterisk
|
An issue was discovered in res_pjsip_diversion.c in Sangoma Asterisk before 13.38.0, 14.x through 16.x before 16.15.0, 17.x before 17.9.0, and 18.x before 18.1.0. A crash can occur when a SIP message…
|
NVD-CWE-noinfo
|
CVE-2020-35652
|
2024-11-21 14:27 |
2021-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208390
|
9.1 |
CRITICAL
Network
|
mitel
|
micollab
|
A library index page in NuPoint Messenger in Mitel MiCollab before 9.2 FP1 could allow an unauthenticated attacker to gain access (view and modify) to user data.
|
NVD-CWE-noinfo
|
CVE-2020-35547
|
2024-11-21 14:27 |
2021-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|