Search Results (359547 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-27991 1 Nagios 1 Nagios Xi 2024-11-21 5.4 Medium
Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field).
CVE-2020-27990 1 Nagios 1 Nagios Xi 2024-11-21 5.4 Medium
Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent).
CVE-2020-27989 1 Nagios 1 Nagios Xi 2024-11-21 5.4 Medium
Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard).
CVE-2020-27988 1 Nagios 1 Nagios Xi 2024-11-21 5.4 Medium
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
CVE-2020-27986 1 Sonarsource 1 Sonarqube 2024-11-21 7.5 High
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it.
CVE-2020-27985 1 Securityonionsolutions 1 Security Onion 2024-11-21 7.8 High
Security Onion v2 prior to 2.3.10 has an incorrect sudo configuration, which allows the administrative user to obtain root access without using the sudo password by editing and executing /home/<user>/SecurityOnion/setup/so-setup.
CVE-2020-27982 1 Icewarp 1 Mail Server 2024-11-21 6.1 Medium
IceWarp 11.4.5.0 allows XSS via the language parameter.
CVE-2020-27980 1 Genexis 2 Platinum-4410, Platinum-4410 Firmware 2024-11-21 5.4 Medium
Genexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to perform malicious actions in which the XSS popup will affect all privileged users.
CVE-2020-27978 1 Shibboleth 1 Identity Provider 2024-11-21 7.5 High
Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause a login flow to trigger Java heap exhaustion due to the creation of objects in the Java Servlet container session.
CVE-2020-27977 1 Capasystems 1 Capainstaller 2024-11-21 7.8 High
CapaSystems CapaInstaller before 6.0.101 does not properly assign, modify, or check privileges for an actor who attempts to edit registry values, allowing an attacker to escalate privileges.
CVE-2020-27976 1 Oscommerce 1 Oscommerce 2024-11-21 9.8 Critical
osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the application. This affects the PHP mail function, and the sendmail -f option.
CVE-2020-27975 1 Oscommerce 1 Oscommerce 2024-11-21 8.8 High
osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.
CVE-2020-27974 1 Quadient 1 Mail Accounting 2024-11-21 6.1 Medium
NeoPost Mail Accounting Software Pro 5.0.6 allows php/Commun/FUS_SCM_BlockStart.php?code= XSS.
CVE-2020-27970 1 Yandex 1 Yandex Browser 2024-11-21 5.3 Medium
Yandex Browser before 20.10.0 allows remote attackers to spoof the address bar
CVE-2020-27969 1 Yandex 1 Yandex Browser 2024-11-21 7.3 High
Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing
CVE-2020-27958 1 Osu 1 Ohio Supercomputer Center Open Ondemand 2024-11-21 4.3 Medium
The Job Composer app in Ohio Supercomputer Center Open OnDemand before 1.7.19 and 1.8.x before 1.8.18 allows remote authenticated users to provide crafted input in a job template.
CVE-2020-27957 1 Mediawiki 1 Mediawiki 2024-11-21 5.4 Medium
The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certain varieties of games were created within MediaWiki, their names or titles could be manipulated to generate stored XSS within the RandomGameUnit extension.
CVE-2020-27956 1 Car Rental Management System Project 1 Car Rental Management System 2024-11-21 9.8 Critical
An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the user to conduct remote code execution via admin/index.php?page=manage_car because .php files can be uploaded to admin/assets/uploads/ (under the web root).
CVE-2020-27955 1 Git Large File Storage Project 1 Git Large File Storage 2024-11-21 9.8 Critical
Git LFS 2.12.0 allows Remote Code Execution.
CVE-2020-27952 1 Apple 2 Mac Os X, Macos 2024-11-21 7.8 High
An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. Processing a maliciously crafted font file may lead to arbitrary code execution.