|
209091
|
9.8 |
CRITICAL
Network
|
arubanetworks
|
arubaos sd-wan
|
There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially crafted packets destined to the PAPI (Aruba Networks AP management pr…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-24633
|
2024-11-21 14:15 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209092
|
4.8 |
MEDIUM
Network
|
user_registration_\&_login_and_user_management_system_project
|
user_registration_\&_login_and_user_management_system
|
Cross Site Scripting (XSS) vulnerability in the Registration page of the admin panel in PHPGurukul User Registration & Login and User Management System With admin panel 2.1.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24723
|
2024-11-21 14:15 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209093
|
9.8 |
CRITICAL
Network
|
couchbase
|
couchbase_server
|
Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (aka "magic cookie"). There are cases where the mag…
|
CWE-78
OS Command
|
CVE-2020-24719
|
2024-11-21 14:15 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209094
|
7.5 |
HIGH
Network
|
bab-technologie
|
eibport_firmware
|
BAB TECHNOLOGIE GmbH eibPort V3 prior to 3.8.3 devices allow denial of service (Uncontrolled Resource Consumption) via requests to the lighttpd component.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-24573
|
2024-11-21 14:15 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209095
|
7.5 |
HIGH
Network
|
getgophish
|
gophish
|
Gophish through 0.10.1 does not invalidate the gophish cookie upon logout.
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-24713
|
2024-11-21 14:15 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209096
|
5.4 |
MEDIUM
Network
|
getgophish
|
gophish
|
Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24712
|
2024-11-21 14:15 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209097
|
6.5 |
MEDIUM
Network
|
getgophish
|
gophish
|
The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-24711
|
2024-11-21 14:15 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209098
|
5.3 |
MEDIUM
Network
|
getgophish
|
gophish
|
Gophish before 0.11.0 allows SSRF attacks.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-24710
|
2024-11-21 14:15 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209099
|
5.4 |
MEDIUM
Network
|
getgophish
|
gophish
|
Cross Site Scripting (XSS) vulnerability in Gophish through 0.10.1 via a crafted landing page or email template.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24709
|
2024-11-21 14:15 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209100
|
5.4 |
MEDIUM
Network
|
getgophish
|
gophish
|
Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24708
|
2024-11-21 14:15 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|