|
211791
|
8.1 |
HIGH
Network
|
safervpn
|
safervpn
|
SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could cause a denial of service (DoS) condition, because a symlink from %LOCALAPPDATA…
|
CWE-59
Link Following
|
CVE-2020-25744
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211792
|
6.1 |
MEDIUM
Network
|
webtareas_project
|
webtareas
|
webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement.php, administration/departments.php, administration/locations.php, expenses/cl…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25735
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211793
|
5.3 |
MEDIUM
Network
|
webtareas_project
|
webtareas
|
webTareas through 2.1 allows files/Default/ Directory Listing.
|
CWE-22
Path Traversal
|
CVE-2020-25734
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211794
|
7.5 |
HIGH
Network
|
webtareas_project
|
webtareas
|
webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-25733
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211795
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25729
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211796
|
9.8 |
CRITICAL
Network
|
sqreen
|
python_mini_racer
|
A heap overflow in Sqreen PyMiniRacer (aka Python Mini Racer) before 0.3.0 allows remote attackers to potentially exploit heap corruption.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-25489
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211797
|
8.8 |
HIGH
Network
|
alfresco
|
reset_password
|
The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2020-25728
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211798
|
7.5 |
HIGH
Network
|
flexsolution
|
reset_password
|
The Reset Password add-on before 1.2.0 for Alfresco suffers from CMIS-SQL Injection, which allows a malicious user to inject a query within the email input field.
|
CWE-89
SQL Injection
|
CVE-2020-25727
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211799
|
7.3 |
HIGH
Network
|
sqreen
|
php_microagent
|
Lack of cryptographic signature verification in the Sqreen PHP agent daemon before 1.16.0 makes it easier for remote attackers to inject rules for execution inside the virtual machine.
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-25490
|
2024-11-21 14:18 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211800
|
9.8 |
CRITICAL
Network
|
xmlquery_project
|
xmlquery
|
xmlquery before 1.3.1 lacks a check for whether a LoadURL response is in the XML format, which allows attackers to cause a denial of service (SIGSEGV) at xmlquery.(*Node).InnerText or possibly have u…
|
CWE-119 CWE-20
Incorrect Access of Indexable Resource ('Range Error') Improper Input Validation
|
CVE-2020-25614
|
2024-11-21 14:18 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|