Show filters
373 Total Results
Displaying 151-160 of 373
Sort by:
Attacker Value
Unknown
CVE-2020-36324
Disclosure Date: April 21, 2021 (last updated February 22, 2025)
Wikimedia Quarry analytics-quarry-web before 2020-12-15 allows Reflected XSS because app.py does not explicitly set the application/json content type.
0
Attacker Value
Unknown
CVE-2021-21305
Disclosure Date: February 08, 2021 (last updated February 22, 2025)
CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1, there is a code injection vulnerability. The "#manipulate!" method inappropriately evals the content of mutation option(:read/:write), allowing attackers to craft a string that can be executed as a Ruby code. If an application developer supplies untrusted inputs to the option, it will lead to remote code execution(RCE). This is fixed in versions 1.3.2 and 2.1.1.
0
Attacker Value
Unknown
CVE-2021-21288
Disclosure Date: February 08, 2021 (last updated February 22, 2025)
CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1 the download feature has an SSRF vulnerability, allowing attacks to provide DNS entries or IP addresses that are intended for internal use and gather information about the Intranet infrastructure of the platform. This is fixed in versions 1.3.2 and 2.1.1.
0
Attacker Value
Unknown
CVE-2020-26052
Disclosure Date: February 08, 2021 (last updated February 22, 2025)
Online Marriage Registration System 1.0 is affected by stored cross-site scripting (XSS) vulnerabilities in multiple parameters.
0
Attacker Value
Unknown
CVE-2020-35888
Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the arr crate through 2020-08-25 for Rust. Uninitialized memory is dropped by Array::new_from_template.
0
Attacker Value
Unknown
CVE-2020-35886
Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the arr crate through 2020-08-25 for Rust. An attacker can smuggle non-Sync/Send types across a thread boundary to cause a data race.
0
Attacker Value
Unknown
CVE-2020-35887
Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the arr crate through 2020-08-25 for Rust. There is a buffer overflow in Index and IndexMut.
0
Attacker Value
Unknown
CVE-2020-35900
Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the array-queue crate through 2020-09-26 for Rust. A pop_back() call may lead to a use-after-free.
0
Attacker Value
Unknown
CVE-2020-27720
Disclosure Date: December 24, 2020 (last updated November 28, 2024)
On BIG-IP LTM/CGNAT version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.5, when processing NAT66 traffic with Port Block Allocation (PBA) mode and SP-DAG enabled, and dag-ipv6-prefix-len configured with a value less than the default of 128, an undisclosed traffic pattern may cause the Traffic Management Microkernel (TMM) to restart.
0
Attacker Value
Unknown
CVE-2020-35136
Disclosure Date: December 23, 2020 (last updated February 22, 2025)
Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload into the filename for the zipfilename_template parameter to admin/tools/dolibarr_export.php.
0