|
209001
|
5.4 |
MEDIUM
Network
|
elkarbackup
|
elkarbackup
|
A Persistent Cross-site Scripting vulnerability is found in ElkarBackup v1.3.3, where an attacker can steal the user session cookie using this vulnerability present on Policies >> action >> Name Para…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24924
|
2024-11-21 14:16 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209002
|
9.8 |
CRITICAL
Network
|
yaws debian canonical
|
yaws debian_linux ubuntu_linux
|
CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
|
CWE-78
OS Command
|
CVE-2020-24916
|
2024-11-21 14:16 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209003
|
6.1 |
MEDIUM
Network
|
kentico
|
kentico
|
Cross Site Scripting (XSS) vulnerability in Kentico before 12.0.75.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24794
|
2024-11-21 14:16 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209004
|
9.8 |
CRITICAL
Network
|
tendacn
|
ac18_firmware
|
Tenda AC18 Router through V15.03.05.05_EN and through V15.03.05.19(6318) CN devices could cause a remote code execution due to incorrect authentication handling of vulnerable logincheck() function in…
|
CWE-287
Improper Authentication
|
CVE-2020-24987
|
2024-11-21 14:16 |
2020-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209005
|
7.2 |
HIGH
Network
|
concretecms
|
concrete_cms
|
Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to modify site configuration to upload the PHP file and…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-24986
|
2024-11-21 14:16 |
2020-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209006
|
5.3 |
MEDIUM
Network
|
ucms_project
|
ucms
|
An Incorrect Access Control vulnerability exists in /ucms/chk.php in UCMS 1.4.8. This results in information leak via an error message caused by directly accessing the website built by UCMS.
|
NVD-CWE-noinfo
|
CVE-2020-24981
|
2024-11-21 14:16 |
2020-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209007
|
5.4 |
MEDIUM
Network
|
appsbd
|
best_support_system
|
An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24963
|
2024-11-21 14:16 |
2020-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209008
|
9.8 |
CRITICAL
Network
|
noise-java_project
|
noise-java
|
An issue was discovered in Noise-Java through 2020-08-27. AESGCMOnCtrCipherState.encryptWithAd() allows out-of-bounds access.
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-25023
|
2024-11-21 14:16 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209009
|
9.8 |
CRITICAL
Network
|
noise-java_project
|
noise-java
|
An issue was discovered in Noise-Java through 2020-08-27. AESGCMFallbackCipherState.encryptWithAd() allows out-of-bounds access.
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-25022
|
2024-11-21 14:16 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209010
|
9.8 |
CRITICAL
Network
|
noise-java_project
|
noise-java
|
An issue was discovered in Noise-Java through 2020-08-27. ChaChaPolyCipherState.encryptWithAd() allows out-of-bounds access.
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-25021
|
2024-11-21 14:16 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|