|
196501
|
6.5 |
MEDIUM
Network
|
icegram
|
email_subscribers_\&_newsletters
|
Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted l…
|
CWE-352
Origin Validation Error
|
CVE-2020-5767
|
2024-11-21 14:34 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196502
|
9.8 |
CRITICAL
Network
|
grandstream
|
ucm6202_firmware ucm6204_firmware ucm6208_firmware
|
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can execute commands as the root user by issuing a spec…
|
CWE-78
OS Command
|
CVE-2020-5759
|
2024-11-21 14:34 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196503
|
8.8 |
HIGH
Network
|
grandstream
|
ucm6202_firmware ucm6204_firmware ucm6208_firmware
|
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can execute commands as the root user by sending a cra…
|
CWE-78
OS Command
|
CVE-2020-5758
|
2024-11-21 14:34 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196504
|
9.8 |
CRITICAL
Network
|
grandstream
|
ucm6202_firmware ucm6204_firmware ucm6208_firmware
|
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can bypass command injection mitigations and execute c…
|
CWE-78
OS Command
|
CVE-2020-5757
|
2024-11-21 14:34 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196505
|
8.8 |
HIGH
Network
|
grandstream
|
gwn7000_firmware
|
Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitra…
|
CWE-78
OS Command
|
CVE-2020-5756
|
2024-11-21 14:34 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196506
|
5.4 |
MEDIUM
Network
|
tenable
|
nessus
|
Nessus 8.10.0 and earlier were found to contain a Stored XSS vulnerability due to improper validation of input during scan configuration. An authenticated, remote attacker could potentially exploit t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5765
|
2024-11-21 14:34 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196507
|
7.5 |
HIGH
Network
|
dell
|
emc_omimssc_for_scvmm emc_omimssc_for_sccm
|
Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain a hard-coded cryptographic key vulnerability. A remote unauthenticated attacke…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-5374
|
2024-11-21 14:34 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196508
|
7.5 |
HIGH
Network
|
dell
|
emc_omimssc_for_scvmm emc_omimssc_for_sccm
|
Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain an improper authentication vulnerability. A remote unauthenticated attacker ma…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-5373
|
2024-11-21 14:34 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196509
|
7.5 |
HIGH
Network
|
srs_simple_hits_counter_project
|
srs_simple_hits_counter
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3 and 1.0.4 allows a remote, unauthenticated attacker to deter…
|
CWE-89
SQL Injection
|
CVE-2020-5766
|
2024-11-21 14:34 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196510
|
6.1 |
MEDIUM
Network
|
ss-proj
|
shirasagi
|
Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
|
CWE-601
Open Redirect
|
CVE-2020-5607
|
2024-11-21 14:34 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|