Show filters
373 Total Results
Displaying 151-160 of 373
Sort by:
Attacker Value
Unknown

CVE-2020-36324

Disclosure Date: April 21, 2021 (last updated February 22, 2025)
Wikimedia Quarry analytics-quarry-web before 2020-12-15 allows Reflected XSS because app.py does not explicitly set the application/json content type.
Attacker Value
Unknown

CVE-2021-21305

Disclosure Date: February 08, 2021 (last updated February 22, 2025)
CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1, there is a code injection vulnerability. The "#manipulate!" method inappropriately evals the content of mutation option(:read/:write), allowing attackers to craft a string that can be executed as a Ruby code. If an application developer supplies untrusted inputs to the option, it will lead to remote code execution(RCE). This is fixed in versions 1.3.2 and 2.1.1.
Attacker Value
Unknown

CVE-2021-21288

Disclosure Date: February 08, 2021 (last updated February 22, 2025)
CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1 the download feature has an SSRF vulnerability, allowing attacks to provide DNS entries or IP addresses that are intended for internal use and gather information about the Intranet infrastructure of the platform. This is fixed in versions 1.3.2 and 2.1.1.
Attacker Value
Unknown

CVE-2020-26052

Disclosure Date: February 08, 2021 (last updated February 22, 2025)
Online Marriage Registration System 1.0 is affected by stored cross-site scripting (XSS) vulnerabilities in multiple parameters.
Attacker Value
Unknown

CVE-2020-35888

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the arr crate through 2020-08-25 for Rust. Uninitialized memory is dropped by Array::new_from_template.
Attacker Value
Unknown

CVE-2020-35886

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the arr crate through 2020-08-25 for Rust. An attacker can smuggle non-Sync/Send types across a thread boundary to cause a data race.
Attacker Value
Unknown

CVE-2020-35887

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the arr crate through 2020-08-25 for Rust. There is a buffer overflow in Index and IndexMut.
Attacker Value
Unknown

CVE-2020-35900

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the array-queue crate through 2020-09-26 for Rust. A pop_back() call may lead to a use-after-free.
Attacker Value
Unknown

CVE-2020-27720

Disclosure Date: December 24, 2020 (last updated November 28, 2024)
On BIG-IP LTM/CGNAT version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.5, when processing NAT66 traffic with Port Block Allocation (PBA) mode and SP-DAG enabled, and dag-ipv6-prefix-len configured with a value less than the default of 128, an undisclosed traffic pattern may cause the Traffic Management Microkernel (TMM) to restart.
Attacker Value
Unknown

CVE-2020-35136

Disclosure Date: December 23, 2020 (last updated February 22, 2025)
Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload into the filename for the zipfilename_template parameter to admin/tools/dolibarr_export.php.