|
211521
|
6.7 |
MEDIUM
Local
|
acronis
|
true_image
|
Acronis True Image through 2021 on macOS allows local privilege escalation from admin to root due to insecure folder permissions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-25593
|
2024-11-21 14:18 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211522
|
5.4 |
MEDIUM
Network
|
codologic
|
codoforum
|
A stored cross site scripting (XSS) vulnerability in the 'Manage Users' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload enter…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25879
|
2024-11-21 14:18 |
2021-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211523
|
4.8 |
MEDIUM
Network
|
blackcat-cms
|
blackcat_cms
|
A stored cross site scripting (XSS) vulnerability in the 'Admin-Tools' feature of BlackCat CMS 1.3.6 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads enter…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25878
|
2024-11-21 14:18 |
2021-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211524
|
5.4 |
MEDIUM
Network
|
blackcat-cms
|
blackcat_cms
|
A stored cross site scripting (XSS) vulnerability in the 'Add Page' feature of BlackCat CMS 1.3.6 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25877
|
2024-11-21 14:18 |
2021-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211525
|
5.4 |
MEDIUM
Network
|
codologic
|
codoforum
|
A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payload entered into t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25876
|
2024-11-21 14:18 |
2021-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211526
|
5.4 |
MEDIUM
Network
|
codologic
|
codoforum
|
A stored cross site scripting (XSS) vulnerability in the 'Smileys' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payload entered into…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25875
|
2024-11-21 14:18 |
2021-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211527
|
6.1 |
MEDIUM
Network
|
icewarp
|
webclient
|
Cross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient 10.3.5 allows remote attackers to inject arbitrary web script or HTML via the "p4" field.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25925
|
2024-11-21 14:18 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211528
|
7.5 |
HIGH
Network
|
pexip
|
pexip_infinity
|
Pexip Infinity 22.x through 24.x before 24.2 has Improper Input Validation for call setup. An unauthenticated remote attacker can trigger a software abort (temporary loss of service).
|
CWE-20
Improper Input Validation
|
CVE-2020-25868
|
2024-11-21 14:18 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211529
|
8.8 |
HIGH
Network
|
enphase
|
envoy_firmware
|
An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /installer/upgrade_start allows remote authenticated users to execute arbitrary comma…
|
CWE-78
OS Command
|
CVE-2020-25755
|
2024-11-21 14:18 |
2021-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211530
|
7.5 |
HIGH
Network
|
enphase
|
envoy_firmware
|
An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents traditional user authentication. This module uses a password deri…
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2020-25754
|
2024-11-21 14:18 |
2021-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|