
Look up vulnerabilities by software, product or CVE number.
| CVE | Published | CVSS | ShadowTrackr CVSS | Summary |
|---|---|---|---|---|
CVE: CVE-2020-1754 | Published 2022-08-05 | CVSS: 4.3 | ShadowTrackr CVSS: 1.3 | Summary: In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups. |
CVE: CVE-2020-17541 | Published 2021-06-01 | CVSS: 8.8 | ShadowTrackr CVSS: 6.6 | Summary: Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service. |
CVE: CVE-2020-17542 | Published 2021-04-23 | CVSS: 5.4 | ShadowTrackr CVSS: 0.4 | Summary: Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious payload into the "Task Detail" comment window of the "/dotAdmin/#/c/workflow" component. |