
Look up vulnerabilities by software, product or CVE number.
| CVE | Published | CVSS | ShadowTrackr CVSS | Summary |
|---|---|---|---|---|
CVE: CVE-2020-2502 | Published 2021-02-17 | CVSS: 6.1 | ShadowTrackr CVSS: 0.5 | Summary: This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. Photo Station 6.0.11 and later |
CVE: CVE-2020-25023 | Published 2020-09-04 | CVSS: 9.8 | ShadowTrackr CVSS: 8.2 | Summary: An issue was discovered in Noise-Java through 2020-08-27. AESGCMOnCtrCipherState.encryptWithAd() allows out-of-bounds access. |
CVE: CVE-2020-25022 | Published 2020-09-04 | CVSS: 9.8 | ShadowTrackr CVSS: 8.2 | Summary: An issue was discovered in Noise-Java through 2020-08-27. AESGCMFallbackCipherState.encryptWithAd() allows out-of-bounds access. |
CVE: CVE-2020-25021 | Published 2020-09-04 | CVSS: 9.8 | ShadowTrackr CVSS: 8.2 | Summary: An issue was discovered in Noise-Java through 2020-08-27. ChaChaPolyCipherState.encryptWithAd() allows out-of-bounds access. |
CVE: CVE-2020-25025 | Published 2020-09-02 | CVSS: 4.3 | ShadowTrackr CVSS: 1.3 | Summary: The l10nmgr (aka Localization Manager) extension before 7.4.0, 8.x before 8.7.0, and 9.x before 9.2.0 for TYPO3 allows Information Disclosure (translatable fields). |
CVE: CVE-2020-25026 | Published 2020-09-02 | CVSS: 4.3 | ShadowTrackr CVSS: 1.3 | Summary: The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows Information Disclosure (participant data, and event data via email) because of Broken Access Control. |
CVE: CVE-2020-25020 | Published 2020-08-29 | CVSS: 9.8 | ShadowTrackr CVSS: 8.2 | Summary: MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components. |