|
199801
|
9.8 |
CRITICAL
Network
|
nagios
|
fusion
|
Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.php.
|
CWE-77
Command Injection
|
CVE-2020-28901
|
2024-11-21 14:23 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199802
|
9.8 |
CRITICAL
Network
|
nagios
|
fusion nagios_xi
|
Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to …
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-28900
|
2024-11-21 14:23 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199803
|
6.1 |
MEDIUM
Network
|
projectworlds
|
travel_management_system
|
XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via the name field
|
CWE-79
Cross-site Scripting
|
CVE-2020-29205
|
2024-11-21 14:23 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199804
|
5.4 |
MEDIUM
Network
|
deskpro
|
deskpro
|
Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to an account takeover via custom email templates.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28722
|
2024-11-21 14:23 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199805
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite 7.10.4 and earlier allows XSS via crafted content to reach an undocumented feature, such as 
|
CVE-2020-28943
|
2024-11-21 14:23 |
2021-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199808
|
7.5 |
HIGH
Network
|
abus
|
secvest_wireless_alarm_system_fuaa50000_firmware
|
The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can use this vulnerability to obtain sensitive inform…
|
CWE-287
Improper Authentication
|
CVE-2020-28973
|
2024-11-21 14:23 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199809
|
5.3 |
MEDIUM
Network
|
resourcexpress
|
resourcexpress
|
In QED ResourceXpress through 4.9k, a large numeric or alphanumeric value submitted in specific URL parameters causes a server error in script execution due to insufficient input validation.
|
CWE-20
Improper Input Validation
|
CVE-2020-28898
|
2024-11-21 14:23 |
2021-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199810
|
9.8 |
CRITICAL
Network
|
monitorr
|
monitorr
|
An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows an unauthorized person to create valid credentials.
|
CWE-863
Incorrect Authorization
|
CVE-2020-28872
|
2024-11-21 14:23 |
2021-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|