ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

7 results for “CVE-2020-1900”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-19003
Published
2021-10-06
CVSS:
5.3
ShadowTrackr CVSS:
2.9
Summary:
An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list.
CVE:
CVE-2020-19002
Published
2021-08-27
CVSS:
6.1
ShadowTrackr CVSS:
0.5
Summary:
Cross Site Scripting (XSS) in Mezzanine v4.3.1 allows remote attackers to execute arbitrary code via the 'Description' field of the component 'admin/blog/blogpost/add/'. This issue is different than CVE-2018-16632.
CVE:
CVE-2020-19000
Published
2021-08-27
CVSS:
6.1
ShadowTrackr CVSS:
0.5
Summary:
Cross Site Scripting (XSS) in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary code via line 54 of the component 'simiki/blob/master/simiki/generators.py'.
CVE:
CVE-2020-19001
Published
2021-08-27
CVSS:
9.8
ShadowTrackr CVSS:
8.2
Summary:
Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 of the component 'simiki/blob/master/simiki/config.py'.
CVE:
CVE-2020-1900
Published
2021-03-11
CVSS:
9.8
ShadowTrackr CVSS:
7.2
Summary:
When unserializing an object with dynamic properties HHVM needs to pre-reserve the full size of the dynamic property array before inserting anything into it. Otherwise the array might resize, invalidating previously stored references. This pre-reservation was not occurring in HHVM prior to v4.32.3, between versions 4.33.0 and 4.56.0, 4.57.0, 4.58.0, 4.58.1, 4.59.0, 4.60.0, 4.61.0, 4.62.0.
CVE:
CVE-2020-19007
Published
2020-08-26
CVSS:
5.4
ShadowTrackr CVSS:
0.4
Summary:
Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then execute in the victim user's browser.
CVE:
CVE-2020-19005
Published
2020-08-25
CVSS:
5.7
ShadowTrackr CVSS:
1.9
Summary:
zrlog v2.1.0 has a vulnerability with the permission check. If admin account is logged in, other unauthorized users can download the database backup file directly.