ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

5 results for “CVE-2020-3538”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-3538
Published
2024-11-18
CVSS:
4.6
ShadowTrackr CVSS:
0.4
Summary:
A vulnerability in a certain REST API endpoint of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to perform a path traversal attack on an affected device. The vulnerability is due to insufficient path restriction enforcement. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to overwrite or list arbitrary files on the affected device.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
CVE:
CVE-2020-35388
Published
2020-12-26
CVSS:
7.5
ShadowTrackr CVSS:
4.6
Summary:
rainrocka xinhu 2.1.9 allows remote attackers to obtain sensitive information via an index.php?a=gettotal request in which the ajaxbool value is manipulated to be true.
CVE:
CVE-2020-35381
Published
2020-12-15
CVSS:
7.5
ShadowTrackr CVSS:
6.9
Summary:
jsonparser 1.0.0 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a GET call.
CVE:
CVE-2020-35380
Published
2020-12-15
CVSS:
7.5
ShadowTrackr CVSS:
4.6
Summary:
GJSON before 1.6.4 allows attackers to cause a denial of service via crafted JSON.
CVE:
CVE-2020-35382
Published
2020-12-14
CVSS:
7.2
ShadowTrackr CVSS:
4.8
Summary:
SQL Injection in Classbooking before 2.4.1 via the username field of a CSV file when adding a new user.