CVE-2020-26217
- EPSS 93.01%
- Veröffentlicht 16.11.2020 21:15:12
- Zuletzt bearbeitet 23.05.2025 16:54:19
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone...
CVE-2020-25694
- EPSS 0.36%
- Veröffentlicht 16.11.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:29
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client application that creates additional database connections only reuses the basic connection parameters while drop...
CVE-2020-25695
- EPSS 22.67%
- Veröffentlicht 16.11.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:29
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions un...
CVE-2020-8695
- EPSS 0.15%
- Veröffentlicht 12.11.2020 18:15:16
- Zuletzt bearbeitet 21.11.2024 05:39:16
Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
CVE-2020-8696
- EPSS 0.24%
- Veröffentlicht 12.11.2020 18:15:16
- Zuletzt bearbeitet 21.11.2024 05:39:16
Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
CVE-2020-8698
- EPSS 0.27%
- Veröffentlicht 12.11.2020 18:15:16
- Zuletzt bearbeitet 21.11.2024 05:39:17
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
CVE-2020-25706
- EPSS 1.46%
- Veröffentlicht 12.11.2020 14:15:22
- Zuletzt bearbeitet 21.11.2024 05:18:32
A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template import preview in the xml_path field
CVE-2020-28368
- EPSS 0.07%
- Veröffentlicht 10.11.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:22:40
Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically i...
CVE-2020-25074
- EPSS 12.81%
- Veröffentlicht 10.11.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:12
The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use this to achieve remote code execution.
CVE-2017-18926
- EPSS 2.76%
- Veröffentlicht 06.11.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 03:21:16
raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen in raptor_qname_format_as_xml).