Search

Search Results (370172 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-7982 1 Openwrt 2 Lede, Openwrt 2024-11-21 8.1 High
An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the opkg package manager before 2020-01-25 prevents correct parsing of embedded checksums in the signed repository index, allowing a man-in-the-middle attacker to inject arbitrary package payloads (which are installed without verification).
CVE-2020-7981 1 Rubygeocoder 1 Geocoder 2024-11-21 9.8 Critical
sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data.
CVE-2020-7980 1 Intelliantech 1 Aptus Web 2024-11-21 9.8 Critical
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. NOTE: a valid sid cookie for a login to the intellian default account might be needed.
CVE-2020-7979 1 Gitlab 1 Gitlab 2024-11-21 5.3 Medium
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
CVE-2020-7978 1 Gitlab 1 Gitlab 2024-11-21 7.5 High
GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.
CVE-2020-7977 1 Gitlab 1 Gitlab 2024-11-21 5.3 Medium
GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.
CVE-2020-7976 1 Gitlab 1 Gitlab 2024-11-21 5.3 Medium
GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control.
CVE-2020-7974 1 Gitlab 1 Gitlab 2024-11-21 5.3 Medium
GitLab EE 10.1 through 12.7.2 allows Information Disclosure.
CVE-2020-7973 1 Gitlab 1 Gitlab 2024-11-21 6.1 Medium
GitLab through 12.7.2 allows XSS.
CVE-2020-7972 1 Gitlab 1 Gitlab 2024-11-21 7.5 High
GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).
CVE-2020-7971 1 Gitlab 1 Gitlab 2024-11-21 6.1 Medium
GitLab EE 11.0 and later through 12.7.2 allows XSS.
CVE-2020-7969 1 Gitlab 1 Gitlab 2024-11-21 7.5 High
GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.
CVE-2020-7968 1 Gitlab 1 Gitlab 2024-11-21 7.5 High
GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.
CVE-2020-7967 1 Gitlab 1 Gitlab 2024-11-21 4.3 Medium
GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).
CVE-2020-7966 1 Gitlab 1 Gitlab 2024-11-21 7.5 High
GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.
CVE-2020-7965 1 Webargs Project 1 Webargs 2024-11-21 8.8 High
flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input. If the request body is valid JSON, it will accept it even if the content type is application/x-www-form-urlencoded. This allows for JSON POST requests to be made across domains, leading to CSRF.
CVE-2020-7964 1 Mirumee 1 Saleor 2024-11-21 5.3 Medium
An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user ID and consequently leak user data (e.g., name, address, and previous orders of any other customer).
CVE-2020-7962 1 Oneidentity 1 Password Manager 2024-11-21 5.3 Medium
An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It is possible for an attacker to detect a valid answer based on the HTTP response content, and reuse this answer later for a password reset on a chosen password. The enumeration is possible because, within the HTTP response content, WRONG ID is only returned when the answer is incorrect.
CVE-2020-7959 1 Labvantage 1 Labvantage 2024-11-21 5.3 Medium
LabVantage LIMS 8.3 does not properly maintain the confidentiality of database names. For example, the web application exposes the database name. An attacker might be able to enumerate database names by providing his own database name in a request, because the response will return an 'Unrecognized Database exception message if the database does not exist.
CVE-2020-7958 1 Oneplus 2 Oneplus 7 Pro, Oneplus 7 Pro Firmware 2024-11-21 6.0 Medium
An issue was discovered on OnePlus 7 Pro devices before 10.0.3.GM21BA. The firmware was found to contain functionality that allows a privileged user (root) in the Rich Execution Environment (REE) to obtain bitmap images from the fingerprint sensor because of Leftover Debug Code. The issue is that the Trusted Application (TA) supports an extended number of commands beyond what is needed to implement a fingerprint authentication system compatible with Android. An attacker who is in the position to send commands to the TA (for example, the root user) is able to send a sequence of these commands that will result in the TA sending a raw fingerprint image to the REE. This means that the Trusted Execution Environment (TEE) no longer protects identifiable fingerprint data from the REE.