|
199591
|
4.8 |
MEDIUM
Network
|
netartmedia
|
news_lister
|
In NetArt News Lister 1.0.0, the news headlines vulnerable to stored xss attacks. Attackers can inject codes in news titles.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29364
|
2024-11-21 14:23 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199592
|
9.8 |
CRITICAL
Network
|
readymedia_project debian
|
readymedia debian_linux
|
ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug re…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-28926
|
2024-11-21 14:23 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199593
|
5.5 |
MEDIUM
Local
|
advsys
|
pngout
|
An issue was discovered in PNGOUT 2020-01-15. When compressing a crafted PNG file, it encounters an integer overflow.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-29384
|
2024-11-21 14:23 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199594
|
5.3 |
MEDIUM
Network
|
canto
|
canto
|
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/tree.php?subdoma…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-28978
|
2024-11-21 14:23 |
2020-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199595
|
5.3 |
MEDIUM
Network
|
canto
|
canto
|
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/get.php?subdomai…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-28977
|
2024-11-21 14:23 |
2020-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199596
|
5.3 |
MEDIUM
Network
|
canto
|
canto
|
The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/detail.php?sub…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-28976
|
2024-11-21 14:23 |
2020-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199597
|
9.8 |
CRITICAL
Network
|
fujitsu
|
eternus_storage_dx200_s4_firmware
|
An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as a root user (using any web browser), the portal can be accessed with root priv…
|
CWE-287
Improper Authentication
|
CVE-2020-29127
|
2024-11-21 14:23 |
2020-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199598
|
7.8 |
HIGH
Local
|
vsolcn
|
v1600d4l_firmware v1600d-mini_firmware
|
An issue was discovered on V-SOL V1600D4L V1.01.49 and V1600D-MINI V1.01.48 OLT devices. A hardcoded RSA private key (specific to V1600D4L and V1600D-MINI) is contained in the firmware images.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-29383
|
2024-11-21 14:23 |
2020-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199599
|
7.8 |
HIGH
Local
|
vsolcn
|
v1600d_firmware v1600g1_firmware v1600g2_firmware
|
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. A hardcoded RSA private key (specific to V1600D, V1600G1, and V1600G2) is con…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-29382
|
2024-11-21 14:23 |
2020-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199600
|
9.8 |
CRITICAL
Network
|
vsolcn
|
v1600d_firmware v1600d4l_firmware v1600d-mini_firmware v1600g1_firmware v1600g2_firmware
|
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. Command injection can occur in "uplo…
|
CWE-78
OS Command
|
CVE-2020-29381
|
2024-11-21 14:23 |
2020-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|