|
209581
|
9.8 |
CRITICAL
Network
|
fusionbox
|
widgy
|
Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code via the 'image' widget in the component 'Change Widgy Page'.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-18704
|
2024-11-21 14:08 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209582
|
9.8 |
CRITICAL
Network
|
quokka_project
|
quokka
|
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/utils/atom.py'.
|
CWE-611
XXE
|
CVE-2020-18703
|
2024-11-21 14:08 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209583
|
6.1 |
MEDIUM
Network
|
quokka_project
|
quokka
|
Cross Site Scripting (XSS) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the 'Username' parameter in the component 'quokka/admin/actions.py'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18702
|
2024-11-21 14:08 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209584
|
9.8 |
CRITICAL
Network
|
talelin
|
lin-cms-flask
|
Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token u…
|
CWE-863
Incorrect Authorization
|
CVE-2020-18701
|
2024-11-21 14:08 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209585
|
6.1 |
MEDIUM
Network
|
talelin
|
lin-cms-flask
|
Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts in the the 'Username' parameter of the in component 'app/api/cms/user.py'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18699
|
2024-11-21 14:08 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209586
|
9.8 |
CRITICAL
Network
|
talelin
|
lin-cms-flask
|
Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-18698
|
2024-11-21 14:08 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209587
|
7.5 |
HIGH
Network
|
dcce
|
mac1100_plc_firmware
|
An information disclosure vulnerability exists in the EPA protocol of Dut Computer Control Engineering Co.'s PLC MAC1100.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-18759
|
2024-11-21 14:08 |
2021-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209588
|
9.8 |
CRITICAL
Network
|
dcce
|
mac1100_plc_firmware
|
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code.
|
CWE-77
Command Injection
|
CVE-2020-18758
|
2024-11-21 14:08 |
2021-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209589
|
7.5 |
HIGH
Network
|
dcce
|
mac1100_plc_firmware
|
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to cause persistent denial of service (DOS) via a crafted packet.
|
CWE-862
Missing Authorization
|
CVE-2020-18757
|
2024-11-21 14:08 |
2021-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209590
|
7.5 |
HIGH
Network
|
dcce
|
mac1100_plc_firmware
|
An arbitrary memory access vulnerability in the EPA protocol of Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to read the contents of any variable area.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-18756
|
2024-11-21 14:08 |
2021-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|