|
199561
|
6.1 |
MEDIUM
Network
|
online_examination_system_project
|
online_examination_system
|
Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the q parameter to feedback.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29257
|
2024-11-21 14:23 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199562
|
7.5 |
HIGH
Network
|
plummac
|
ik-401_firmware
|
An improper webserver configuration on Plum IK-401 devices with firmware before 1.02 allows an attacker (with network access to the device) to obtain the configuration file, including hashed credenti…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-28946
|
2024-11-21 14:23 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199563
|
5.5 |
MEDIUM
Local
|
nlnetlabs debian
|
unbound name_server_daemon debian_linux
|
NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that would allow for a local symlink attack. When writing …
|
CWE-59
Link Following
|
CVE-2020-28935
|
2024-11-21 14:23 |
2020-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199564
|
6.1 |
MEDIUM
Network
|
seeddms
|
seeddms
|
Cross-site scripting (XSS) exists in SeedDMS 6.0.13 via the folderid parameter to views/bootstrap/class.DropFolderChooser.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28727
|
2024-11-21 14:23 |
2020-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199565
|
7.8 |
HIGH
Local
|
kaspersky
|
anti-ransomware_tool
|
The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges during installation process.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-28950
|
2024-11-21 14:23 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199566
|
5.5 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-28916
|
2024-11-21 14:23 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199567
|
2.7 |
LOW
Network
|
lightbend
|
play_framework
|
An issue was discovered in Play Framework 2.8.0 through 2.8.4. Carefully crafted JSON payloads sent as a form field lead to Data Amplification. This affects users migrating from a Play version prior …
|
NVD-CWE-Other
|
CVE-2020-28923
|
2024-11-21 14:23 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199568
|
7.2 |
HIGH
Network
|
openclinic_project
|
openclinic
|
OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability allows authenticated users (with substantial privileges) to upload malicious file…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-28939
|
2024-11-21 14:23 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199569
|
5.4 |
MEDIUM
Network
|
openclinic_project
|
openclinic
|
OpenClinic version 0.8.2 is affected by a stored XSS vulnerability in lib/Check.php that allows users of the application to force actions on behalf of other users.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28938
|
2024-11-21 14:23 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199570
|
7.5 |
HIGH
Network
|
openclinic_project
|
openclinic
|
OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to access any patient's medical test results, possibly resulting in disclosure of Prot…
|
CWE-306 CWE-425
Missing Authentication for Critical Function Direct Request ('Forced Browsing')
|
CVE-2020-28937
|
2024-11-21 14:23 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|