|
199171
|
3.5 |
LOW
Network
|
secomea
|
gatemanager_4250_firmware gatemanager_4260_firmware gatemanager_9250_firmware gatemanager_8250_firmware
|
Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim's com…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2020-29023
|
2024-11-21 14:23 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199172
|
5.3 |
MEDIUM
Network
|
secomea
|
gatemanager_4250_firmware gatemanager_4260_firmware gatemanager_9250_firmware gatemanager_8250_firmware
|
Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager all versions prior…
|
NVD-CWE-noinfo
|
CVE-2020-29022
|
2024-11-21 14:23 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199173
|
7.2 |
HIGH
Network
|
open-emr
|
openemr
|
A SQL injection vulnerability in interface/reports/non_reported.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the form_code parameter.
|
CWE-89
SQL Injection
|
CVE-2020-29143
|
2024-11-21 14:23 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199174
|
7.2 |
HIGH
Network
|
open-emr
|
openemr
|
A SQL injection vulnerability in interface/reports/immunization_report.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the form_code paramet…
|
CWE-89
SQL Injection
|
CVE-2020-29140
|
2024-11-21 14:23 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199175
|
7.2 |
HIGH
Network
|
open-emr
|
openemr
|
A SQL injection vulnerability in interface/main/finder/patient_select.php from library/patient.inc in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands v…
|
CWE-89
SQL Injection
|
CVE-2020-29139
|
2024-11-21 14:23 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199176
|
7.2 |
HIGH
Network
|
open-emr
|
openemr
|
A SQL injection vulnerability in interface/usergroup/usergroup_admin.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the schedule_facility p…
|
CWE-89
SQL Injection
|
CVE-2020-29142
|
2024-11-21 14:23 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199177
|
8.1 |
HIGH
Network
|
secomea
|
gatemanager_8250_firmware gatemanager_4250_firmware gatemanager_4260_firmware gatemanager_9250_firmware
|
An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via…
|
CWE-269
Improper Privilege Management
|
CVE-2020-29031
|
2024-11-21 14:23 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199178
|
6.5 |
MEDIUM
Network
|
secomea
|
gatemanager_8250_firmware gatemanager_4250_firmware gatemanager_4260_firmware gatemanager_9250_firmware
|
A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with administrative permissions to read and write arbitrary files in th…
|
CWE-22
Path Traversal
|
CVE-2020-29026
|
2024-11-21 14:23 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199179
|
6.1 |
MEDIUM
Network
|
tipsandtricks-hq
|
wp_security_\&_firewall
|
Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 …
|
CWE-79
Cross-site Scripting
|
CVE-2020-29171
|
2024-11-21 14:23 |
2021-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199180
|
9.8 |
CRITICAL
Network
|
monitorr
|
monitorr
|
Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure file upload.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-28871
|
2024-11-21 14:23 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|