|
197701
|
5.3 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms
|
The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.
|
CWE-20
Improper Input Validation
|
CVE-2020-36175
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197702
|
6.5 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms
|
The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.
|
CWE-352
Origin Validation Error
|
CVE-2020-36174
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197703
|
5.3 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms
|
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2020-36173
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197704
|
6.1 |
MEDIUM
Network
|
advancedcustomfields
|
advanced_custom_fields
|
The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-36172
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197705
|
6.1 |
MEDIUM
Network
|
elementor
|
website_builder
|
The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.
|
CWE-79
Cross-site Scripting
|
CVE-2020-36171
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197706
|
5.3 |
MEDIUM
Network
|
ultimatemember
|
ultimate_member
|
The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms.
|
NVD-CWE-noinfo
|
CVE-2020-36170
|
2024-11-21 14:28 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197707
|
8.8 |
HIGH
Local
|
veritas
|
netbackup opscenter
|
An issue was discovered in Veritas NetBackup through 8.3.0.1 and OpsCenter through 8.3.0.1. Processes using OpenSSL attempt to load and execute libraries from paths that do not exist by default on th…
|
NVD-CWE-noinfo
|
CVE-2020-36169
|
2024-11-21 14:28 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197708
|
8.8 |
HIGH
Local
|
veritas
|
resiliency_platform
|
An issue was discovered in Veritas Resiliency Platform 3.4 and 3.5. It leverages OpenSSL on Windows systems when using the Managed Host addon. On start-up, it loads the OpenSSL library. This library …
|
NVD-CWE-noinfo
|
CVE-2020-36168
|
2024-11-21 14:28 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197709
|
8.8 |
HIGH
Local
|
veritas
|
backup_exec
|
An issue was discovered in the server in Veritas Backup Exec through 16.2, 20.6 before hotfix 298543, and 21.1 before hotfix 657517. On start-up, it loads the OpenSSL library from the Installation fo…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-36167
|
2024-11-21 14:28 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197710
|
9.8 |
CRITICAL
Network
|
1234n
|
minicms
|
Directory traversal vulnerability in post-edit.php in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter.
|
CWE-22
Path Traversal
|
CVE-2020-36052
|
2024-11-21 14:28 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|