|
209961
|
5.4 |
MEDIUM
Network
|
limesurvey
|
limesurvey
|
LimeSurvey before 4.1.12+200324 has stored XSS in application/views/admin/surveysgroups/surveySettings.php and application/models/SurveysGroups.php (aka survey groups).
|
CWE-79
Cross-site Scripting
|
CVE-2020-11456
|
2024-11-21 13:57 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209962
|
9.8 |
CRITICAL
Network
|
limesurvey
|
limesurvey
|
LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php.
|
CWE-22
Path Traversal
|
CVE-2020-11455
|
2024-11-21 13:57 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209963
|
7.5 |
HIGH
Network
|
technicolor
|
tc7337_firmware
|
An issue was discovered on Technicolor TC7337 8.89.17 devices. An attacker can discover admin credentials in the backup file, aka backupsettings.conf.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-11449
|
2024-11-21 13:57 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209964
|
5.3 |
MEDIUM
Network
|
tp-link
|
nc450_firmware nc260_firmware nc250_firmware nc230_firmware nc220_firmware nc210_firmware nc200_firmware kc300s2_firmware kc310s2_firmware kc200_firmware tapo_c200_firmw…
|
TP-Link cloud cameras through 2020-02-09 allow remote attackers to bypass authentication and obtain sensitive information via vectors involving a Wi-Fi session with GPS enabled, aka CNVD-2020-04855.
|
NVD-CWE-noinfo
|
CVE-2020-11445
|
2024-11-21 13:57 |
2020-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209965
|
6.1 |
MEDIUM
Network
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see…
|
CWE-74
Injection
|
CVE-2020-11441
|
2024-11-21 13:57 |
2020-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209966
|
7.5 |
HIGH
Network
|
telerik
|
ui_for_silverlight
|
An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUpload for Silverlight expects a web request that provides the file location of the …
|
CWE-22
Path Traversal
|
CVE-2020-11414
|
2024-11-21 13:57 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209967
|
7.8 |
HIGH
Local
|
psappdeploytoolkit
|
powershell_app_deployment_toolkit
|
In PowerShell App Deployment Toolkit (aka PSAppDeployToolkit) through 3.8.0, an incorrect access control vulnerability in the default configuration may allow an authenticated user to potentially enab…
|
NVD-CWE-Other
|
CVE-2020-10962
|
2024-11-21 13:56 |
2023-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209968
|
9.8 |
CRITICAL
Network
|
sierrawireless
|
airlink_mobility_manager
|
Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges.
|
NVD-CWE-noinfo
|
CVE-2020-11101
|
2024-11-21 13:56 |
2022-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209969
|
9.1 |
CRITICAL
Network
|
qualcomm
|
apq8009_firmware apq8017_firmware apq8053_firmware apq8064au_firmware apq8076_firmware apq8084_firmware apq8092_firmware apq8094_firmware apq8096au_firmware aqt1000_firmwar…
|
Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length of frame pointer being accessed in Snapdragon Auto, Snapdragon Compute, Snapdrag…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-11159
|
2024-11-21 13:56 |
2021-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209970
|
7.8 |
HIGH
Local
|
qualcomm
|
aqt1000_firmware ar8035_firmware pm3003a_firmware pm4125_firmware pm456_firmware pm6125_firmware pm6150_firmware pm6150a_firmware pm6150l_firmware pm6250_firmware pm6350…
|
Memory corruption due to buffer overflow while copying the message provided by HLOS into buffer without validating the length of buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-11165
|
2024-11-21 13:56 |
2021-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|