Zephyrnet Logo

CISOs Planning on Bigger Budgets: Report

Date:

Enterprise Vulnerabilities
From DHS/US-CERT’s National Vulnerability Database CVE-2020-26948
PUBLISHED: 2020-10-10

Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.

CVE-2020-26947
PUBLISHED: 2020-10-10

monero-wallet-gui in Monero GUI 0.17.0.1 includes the . directory in an embedded RPATH (with a preference ahead of /usr/lib), which allows local users to gain privileges via a Trojan horse library in the current working directory.

CVE-2020-26945
PUBLISHED: 2020-10-10

MyBatis before 3.5.6 mishandles deserialization of object streams.

CVE-2020-26934
PUBLISHED: 2020-10-10

phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.

CVE-2020-26935
PUBLISHED: 2020-10-10

An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.

Source: https://www.darkreading.com/vulnerabilities—threats/cisos-planning-on-bigger-budgets-report/d/d-id/1339126?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple

spot_img

Latest Intelligence

spot_img

Chat with us

Hi there! How can I help you?