|
199721
|
6.8 |
MEDIUM
Physics
|
panasonic
|
wv-s2231l_firmware
|
Panasonic Security System WV-S2231L 4.25 has an insecure hard-coded password of lkjhgfdsa (which is just the asdf keyboard row in reverse order).
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-29193
|
2024-11-21 14:23 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199722
|
5.3 |
MEDIUM
Network
|
woocommerce
|
woocommerce
|
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-29156
|
2024-11-21 14:23 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199723
|
6.1 |
MEDIUM
Network
|
cxuu
|
cxuucms
|
CXUUCMS V3 allows XSS via the first and third input fields to /public/admin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29250
|
2024-11-21 14:23 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199724
|
6.1 |
MEDIUM
Network
|
cxuu
|
cxuucms
|
CXUUCMS V3 allows class="layui-input" XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29249
|
2024-11-21 14:23 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199725
|
7.2 |
HIGH
Network
|
zyxel
|
zld vpn_orchestrator nsg_firmware usg_flex_firmware
|
Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-premise before ZLD V4.39 week38, VPN Orchestrator be…
|
CWE-77
Command Injection
|
CVE-2020-29299
|
2024-11-21 14:23 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199726
|
6.1 |
MEDIUM
Network
|
xuxueli
|
xxl-job
|
XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29204
|
2024-11-21 14:23 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199727
|
9.8 |
CRITICAL
Network
|
struct2json_project
|
struct2json
|
struct2json before 2020-11-18 is affected by a Buffer Overflow because strcpy is used for S2J_STRUCT_GET_string_ELEMENT.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-29203
|
2024-11-21 14:23 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199728
|
5.5 |
MEDIUM
Local
|
tengine_project
|
tengine
|
The serializer module in OAID Tengine lite-v1.0 has a Buffer Overflow and crash. NOTE: another person has stated "I don't think there is an proof of overflow so far.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-28759
|
2024-11-21 14:23 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199729
|
6.1 |
MEDIUM
Network
|
litespeedtech
|
litespeed_cache
|
A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29172
|
2024-11-21 14:23 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199730
|
5.5 |
MEDIUM
Local
|
gnome canonical fedoraproject
|
gdk-pixbuf ubuntu_linux fedora
|
GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign t…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-29385
|
2024-11-21 14:23 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|