Show filters
71,618 Total Results
Displaying 921-930 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Low
CVE-2020-14942
Disclosure Date: June 21, 2020 (last updated November 28, 2024)
Tendenci 12.0.10 allows unrestricted deserialization in apps\helpdesk\views\staff.py.
0
Attacker Value
Very Low
CVE-2020-14932
Disclosure Date: June 20, 2020 (last updated November 28, 2024)
compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request. This is related to mailto.php.
0
Attacker Value
Unknown
CVE-2020-14422
Disclosure Date: June 18, 2020 (last updated November 08, 2023)
Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker can cause many dictionary entries to be created. This is fixed in: v3.5.10, v3.5.10rc1; v3.6.12; v3.7.9; v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1; v3.9.0, v3.9.0b4, v3.9.0b5, v3.9.0rc1, v3.9.0rc2.
1
Attacker Value
Unknown
CVE-2020-11901
Disclosure Date: June 17, 2020 (last updated November 28, 2024)
The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.
1
Attacker Value
Unknown
CVE-2020-11899
Disclosure Date: June 17, 2020 (last updated July 25, 2024)
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
1
Attacker Value
Unknown
CVE-2020-12000
Disclosure Date: June 09, 2020 (last updated November 28, 2024)
The affected product is vulnerable to the handling of serialized data. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9.14), allowing an attacker to obtain sensitive information.
1
Attacker Value
Unknown
CVE-2020-12800
Disclosure Date: June 08, 2020 (last updated November 28, 2024)
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.
1
Attacker Value
Very High
CVE-2020-10548
Disclosure Date: June 04, 2020 (last updated November 28, 2024)
rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.
0
Attacker Value
Very High
CVE-2020-10546
Disclosure Date: June 04, 2020 (last updated November 28, 2024)
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.
0
Attacker Value
Very High
CVE-2020-10547
Disclosure Date: June 04, 2020 (last updated November 28, 2024)
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.
0