CVE-2020-29135

CVSS v3 Score
4.1
Medium
CVSS v2 Score
3.5
Low

Vulnerability Description

cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).

CVSS:4.3(Medium)

Inappropriate Encoding for output context vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows a remote attacker to cause MWG to return an ambiguous redirect response via getting a user to ...

CVSS:4.3(Medium)

The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.

CVSS:5.4(Medium)

Proofpoint Enterprise Protection contains a vulnerability in the email delivery agent that allows an unauthenticated attacker to inject improperly encoded HTML into the email body of a message through...

CVSS:9.8(Critical)

Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification.

CVSS:9.8(Critical)

Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control...

CVSS:7.8(High)

util.c in runV 1.0.0 for Docker mishandles a numeric username, which allows attackers to obtain root access by leveraging the presence of an initial numeric value on an /etc/passwd line, and then issu...