|
200621
|
4.8 |
MEDIUM
Network
|
secomea
|
gatemanager_8250_firmware gatemanager_4250_firmware gatemanager_4260_firmware gatemanager_9250_firmware
|
A vulnerability in web UI input field of GateManager allows authenticated attacker to enter script tags that could cause XSS. This issue affects: GateManager all versions prior to 9.3.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29021
|
2024-11-21 14:23 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200622
|
7.3 |
HIGH
Network
|
windriver oracle
|
vxworks communications_eagle
|
In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2020-28895
|
2024-11-21 14:23 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200623
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_opmanager
|
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.
|
NVD-CWE-noinfo
|
CVE-2020-28653
|
2024-11-21 14:23 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200624
|
7.5 |
HIGH
Network
|
rainbowfishsoftware
|
pacsone_server
|
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by file read/manipulation, which can result in remote information disclosure.
|
CWE-22
Path Traversal
|
CVE-2020-29166
|
2024-11-21 14:23 |
2021-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200625
|
9.8 |
CRITICAL
Network
|
rainbowfishsoftware
|
pacsone_server
|
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by incorrect access control, which can result in remotely gaining administrator privileges.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-29165
|
2024-11-21 14:23 |
2021-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200626
|
6.1 |
MEDIUM
Network
|
rainbowfishsoftware
|
pacsone_server
|
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS).
|
CWE-79
Cross-site Scripting
|
CVE-2020-29164
|
2024-11-21 14:23 |
2021-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200627
|
8.8 |
HIGH
Network
|
rainbowfishsoftware
|
pacsone_server
|
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by SQL injection.
|
CWE-89
SQL Injection
|
CVE-2020-29163
|
2024-11-21 14:23 |
2021-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200628
|
7.5 |
HIGH
Network
|
mediawiki
|
mediawiki
|
The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential information disclosure.
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2020-29005
|
2024-11-21 14:23 |
2021-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200629
|
8.8 |
HIGH
Network
|
mediawiki
|
mediawiki
|
The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore facilitated a CSRF attack.
|
CWE-352
Origin Validation Error
|
CVE-2020-29004
|
2024-11-21 14:23 |
2021-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200630
|
4.8 |
MEDIUM
Network
|
online_news_portal_project
|
online_news_portal
|
Online News Portal using PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to inject an arbitrary web script or HTML via the "Title" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29241
|
2024-11-21 14:23 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|