|
199481
|
9.1 |
CRITICAL
Network
|
owncloud
|
owncloud
|
Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to register themselves and have the data directory in the web root. This affects ownC…
|
CWE-20
Improper Input Validation
|
CVE-2020-28645
|
2024-11-21 14:23 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199482
|
4.3 |
MEDIUM
Network
|
owncloud
|
owncloud
|
The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. This affects ownCloud/core version < 10.6.
|
CWE-352
Origin Validation Error
|
CVE-2020-28644
|
2024-11-21 14:23 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199483
|
4.8 |
MEDIUM
Network
|
secomea
|
gatemanager_8250_firmware gatemanager_4250_firmware gatemanager_4260_firmware gatemanager_9250_firmware
|
A vulnerability in web UI input field of GateManager allows authenticated attacker to enter script tags that could cause XSS. This issue affects: GateManager all versions prior to 9.3.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29021
|
2024-11-21 14:23 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199484
|
7.3 |
HIGH
Network
|
windriver oracle
|
vxworks communications_eagle
|
In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2020-28895
|
2024-11-21 14:23 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199485
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_opmanager
|
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.
|
NVD-CWE-noinfo
|
CVE-2020-28653
|
2024-11-21 14:23 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199486
|
7.5 |
HIGH
Network
|
rainbowfishsoftware
|
pacsone_server
|
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by file read/manipulation, which can result in remote information disclosure.
|
CWE-22
Path Traversal
|
CVE-2020-29166
|
2024-11-21 14:23 |
2021-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199487
|
9.8 |
CRITICAL
Network
|
rainbowfishsoftware
|
pacsone_server
|
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by incorrect access control, which can result in remotely gaining administrator privileges.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-29165
|
2024-11-21 14:23 |
2021-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199488
|
6.1 |
MEDIUM
Network
|
rainbowfishsoftware
|
pacsone_server
|
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS).
|
CWE-79
Cross-site Scripting
|
CVE-2020-29164
|
2024-11-21 14:23 |
2021-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199489
|
8.8 |
HIGH
Network
|
rainbowfishsoftware
|
pacsone_server
|
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by SQL injection.
|
CWE-89
SQL Injection
|
CVE-2020-29163
|
2024-11-21 14:23 |
2021-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199490
|
7.5 |
HIGH
Network
|
mediawiki
|
mediawiki
|
The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential information disclosure.
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2020-29005
|
2024-11-21 14:23 |
2021-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|