|
197531
|
5.4 |
MEDIUM
Network
|
alfresco
|
alfresco
|
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT element in an SVG document.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8777
|
2024-11-21 14:39 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197532
|
5.4 |
MEDIUM
Network
|
alfresco
|
alfresco
|
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a file.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8776
|
2024-11-21 14:39 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197533
|
6.1 |
MEDIUM
Network
|
fiserv
|
accurate_reconciliation
|
Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the logout.jsp timeOut parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8952
|
2024-11-21 14:39 |
2020-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197534
|
5.4 |
MEDIUM
Network
|
fiserv
|
accurate_reconciliation
|
Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the Source or Destination field of the Configuration Manager (Configuration Parameter Translation) page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8951
|
2024-11-21 14:39 |
2020-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197535
|
8.1 |
HIGH
Network
|
gurux
|
device_language_message_specification_director
|
An issue was discovered in Gurux GXDLMS Director through 8.5.1905.1301. When downloading OBIS codes, it does not verify that the downloaded files are actual OBIS codes and doesn't check for path trav…
|
CWE-22
Path Traversal
|
CVE-2020-8810
|
2024-11-21 14:39 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197536
|
8.1 |
HIGH
Network
|
gurux
|
device_language_message_specification_director
|
Gurux GXDLMS Director prior to 8.5.1905.1301 downloads updates to add-ins and OBIS code over an unencrypted HTTP connection. A man-in-the-middle attacker can prompt the user to download updates by mo…
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-8809
|
2024-11-21 14:39 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197537
|
6.1 |
MEDIUM
Network
|
wpjobboard
|
wpjobboard
|
The WPJobBoard plugin 5.5.3 for WordPress allows Persistent XSS via the Add Job form, as demonstrated by title and Description.
|
CWE-79
Cross-site Scripting
|
CVE-2020-9019
|
2024-11-21 14:39 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197538
|
5.3 |
MEDIUM
Network
|
litecart
|
litecart
|
LiteCart through 2.2.1 allows admin/?app=users&doc=edit_user CSRF to add a user.
|
CWE-352
Origin Validation Error
|
CVE-2020-9018
|
2024-11-21 14:39 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197539
|
5.4 |
MEDIUM
Network
|
blackboard
|
blackboard_learn
|
Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web script via the Tile widget in the People Tool profile editor.
|
CWE-79
Cross-site Scripting
|
CVE-2020-9008
|
2024-11-21 14:39 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197540
|
8.0 |
HIGH
Network
|
litecart
|
litecart
|
LiteCart through 2.2.1 allows CSV injection via a customer's profile.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-9017
|
2024-11-21 14:39 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|