|
208811
|
4.8 |
MEDIUM
Network
|
s-cart
|
s-cart
|
This affects the package s-cart/core before 4.4. The search functionality of the admin dashboard in core/src/Admin/Controllers/AdminOrderController.phpindex is vulnerable to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28457
|
2024-11-21 14:22 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208812
|
6.1 |
MEDIUM
Network
|
s-cart
|
s-cart
|
The package s-cart/core before 4.4 are vulnerable to Cross-site Scripting (XSS) via the admin panel.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28456
|
2024-11-21 14:22 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208813
|
5.5 |
MEDIUM
Local
|
foxitsoftware
|
foxit_reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF 10.1.0.37527 and earlier. There is a null pointer access/dereference while opening a crafted PDF file, leading the application to crash (denial …
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-28203
|
2024-11-21 14:22 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208814
|
9.8 |
CRITICAL
Network
|
js-data
|
js-data
|
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function.
|
NVD-CWE-Other
|
CVE-2020-28442
|
2024-11-21 14:22 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208815
|
7.3 |
HIGH
Network
|
siemens
|
sicam_a8000_cp-8000_firmware sicam_a8000_cp-8021_firmware sicam_a8000_cp-8022_firmware
|
A vulnerability has been identified in SICAM A8000 CP-8000 (All versions < V16), SICAM A8000 CP-8021 (All versions < V16), SICAM A8000 CP-8022 (All versions < V16). A web server misconfiguration of t…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-28396
|
2024-11-21 14:22 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208816
|
9.8 |
CRITICAL
Network
|
corenlp-js-interface_project
|
corenlp-js-interface
|
All versions of package corenlp-js-interface are vulnerable to Command Injection via the main function.
|
CWE-78
OS Command
|
CVE-2020-28440
|
2024-11-21 14:22 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208817
|
9.8 |
CRITICAL
Network
|
corenlp-js-prefab_project
|
corenlp-js-prefab
|
This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depends on a vulnerable package 'corenlp-js-interface.' Vulnerability can be exploi…
|
CWE-78
OS Command
|
CVE-2020-28439
|
2024-11-21 14:22 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208818
|
6.8 |
MEDIUM
Adjacent
|
schneider-electric
|
modicon_m258_firmware somachine somachine_motion
|
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versions prior to V5.0.4.11) and SoMachine/SoMachine Motion softw…
|
-
|
CVE-2020-28220
|
2024-11-21 14:22 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208819
|
7.8 |
HIGH
Local
|
schneider-electric
|
ecostruxure_geo_scada_expert_2020 ecostruxure_geo_scada_expert_2019
|
A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to September 2020, from 81.7268.1 to 81.7578.1) and Eco…
|
-
|
CVE-2020-28219
|
2024-11-21 14:22 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208820
|
6.5 |
MEDIUM
Network
|
schneider-electric
|
easergy_t300_firmware
|
A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to trick a user into initiating an uninten…
|
-
|
CVE-2020-28218
|
2024-11-21 14:22 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|