Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2020-09-01 CVE-2020-6125 SQL Injection vulnerability in Os4Ed Opensis 7.3
An exploitable SQL injection vulnerability exists in the GetSchool.php functionality of OS4Ed openSIS 7.3.
network
low complexity
os4ed CWE-89
6.5
2020-09-01 CVE-2020-6124 SQL Injection vulnerability in Os4Ed Opensis 7.3
An exploitable sql injection vulnerability exists in the email parameter functionality of OS4Ed openSIS 7.3.
network
low complexity
os4ed CWE-89
6.5
2020-09-01 CVE-2019-5645 Resource Exhaustion vulnerability in Rapid7 Metasploit
By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expression.
network
low complexity
rapid7 CWE-400
5.0
2020-09-01 CVE-2020-7669 Path Traversal vulnerability in U-Root
This affects all versions of package github.com/u-root/u-root/pkg/tarutil.
network
low complexity
u-root CWE-22
5.0
2020-09-01 CVE-2020-7666 Path Traversal vulnerability in U-Root
This affects all versions of package github.com/u-root/u-root/pkg/cpio.
network
low complexity
u-root CWE-22
5.0
2020-09-01 CVE-2020-7665 Path Traversal vulnerability in U-Root
This affects all versions of package github.com/u-root/u-root/pkg/uzip.
network
low complexity
u-root CWE-22
5.0
2020-09-01 CVE-2020-6131 SQL Injection vulnerability in Os4Ed Opensis 7.3
SQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages.
network
low complexity
os4ed CWE-89
6.5
2020-09-01 CVE-2020-6130 SQL Injection vulnerability in Os4Ed Opensis 7.3
SQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages.
network
low complexity
os4ed CWE-89
6.5
2020-09-01 CVE-2020-6129 SQL Injection vulnerability in Os4Ed Opensis 7.3
SQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages.
network
low complexity
os4ed CWE-89
6.5
2020-09-01 CVE-2020-6123 SQL Injection vulnerability in Os4Ed Opensis 7.3
An exploitable sql injection vulnerability exists in the email parameter functionality of OS4Ed openSIS 7.3.
network
low complexity
os4ed CWE-89
6.5