|
209011
|
6.1 |
MEDIUM
Network
|
ecommerce-codeigniter-bootstrap_project
|
ecommerce-codeigniter-bootstrap
|
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminUsers.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25086
|
2024-11-21 14:17 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209012
|
8.8 |
HIGH
Network
|
dlink
|
dcs-2530l_firmware dcs-2670l_firmware
|
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.
|
CWE-77
Command Injection
|
CVE-2020-25079
|
2024-11-21 14:17 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209013
|
7.5 |
HIGH
Network
|
dlink
|
dcs-2530l_firmware dcs-2670l_firmware
|
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.
|
NVD-CWE-noinfo
|
CVE-2020-25078
|
2024-11-21 14:17 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209014
|
5.3 |
MEDIUM
Network
|
debian
|
freedombox
|
FreedomBox through 20.13 allows remote attackers to obtain sensitive information from the /server-status page of the Apache HTTP Server, because a connection from the Tor onion service (or from PageK…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-25073
|
2024-11-21 14:17 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209015
|
8.8 |
HIGH
Network
|
usvn
|
usvn
|
USVN (aka User-friendly SVN) before 1.0.10 allows CSRF, related to the lack of the SameSite Strict feature.
|
CWE-352
Origin Validation Error
|
CVE-2020-25070
|
2024-11-21 14:17 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209016
|
9.8 |
CRITICAL
Network
|
usvn
|
usvn
|
USVN (aka User-friendly SVN) before 1.0.10 allows attackers to execute arbitrary code in the commit view.
|
NVD-CWE-noinfo
|
CVE-2020-25069
|
2024-11-21 14:17 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209017
|
8.8 |
HIGH
Adjacent
|
netgear
|
r8300_firmware
|
NETGEAR R8300 devices before 1.0.2.134 are affected by command injection by an unauthenticated attacker.
|
CWE-77
Command Injection
|
CVE-2020-25067
|
2024-11-21 14:17 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209018
|
7.5 |
HIGH
Network
|
google
|
android
|
An issue was discovered on LG mobile devices with Android OS 4.4, 5.0, 5.1, 6.0, 7.0, 7.1, 8.0, 8.1, 9.0, and 10 software. Key logging may occur because of an obsolete API. The LG ID is LVE-SMP-17001…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-25065
|
2024-11-21 14:17 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209019
|
7.5 |
HIGH
Network
|
google
|
android
|
An issue was discovered on LG mobile devices with Android OS 4.4, 5.0, 5.1, 6.0, 7.0, 7.1, 8.0, 8.1, 9.0, and 10 software. Certain automated testing is mishandled. The LG ID is LVE-SMP-200019 (August…
|
NVD-CWE-noinfo
|
CVE-2020-25064
|
2024-11-21 14:17 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209020
|
7.5 |
HIGH
Network
|
google
|
android
|
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. An application crash can occur because of incorrect application-level input validation. The LG ID is LV…
|
CWE-20
Improper Input Validation
|
CVE-2020-25063
|
2024-11-21 14:17 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|