|
199441
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite 7.10.4 and earlier allows XSS via crafted content to reach an undocumented feature, such as 
|
CVE-2020-28943
|
2024-11-21 14:23 |
2021-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199444
|
7.5 |
HIGH
Network
|
abus
|
secvest_wireless_alarm_system_fuaa50000_firmware
|
The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can use this vulnerability to obtain sensitive inform…
|
CWE-287
Improper Authentication
|
CVE-2020-28973
|
2024-11-21 14:23 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199445
|
5.3 |
MEDIUM
Network
|
resourcexpress
|
resourcexpress
|
In QED ResourceXpress through 4.9k, a large numeric or alphanumeric value submitted in specific URL parameters causes a server error in script execution due to insufficient input validation.
|
CWE-20
Improper Input Validation
|
CVE-2020-28898
|
2024-11-21 14:23 |
2021-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199446
|
9.8 |
CRITICAL
Network
|
monitorr
|
monitorr
|
An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows an unauthorized person to create valid credentials.
|
CWE-863
Incorrect Authorization
|
CVE-2020-28872
|
2024-11-21 14:23 |
2021-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199447
|
8.8 |
HIGH
Adjacent
|
askey
|
rtf3505vw-n1_br_sv_g000_r3505vwn1001_s32_7_firmware
|
Askey Fiber Router RTF3505VW-N1 BR_SV_g000_R3505VWN1001_s32_7 devices allow Remote Code Execution and retrieval of admin credentials to log into the Dashboard or login via SSH, leading to code execut…
|
CWE-78
OS Command
|
CVE-2020-28695
|
2024-11-21 14:23 |
2021-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199448
|
7.5 |
HIGH
Network
|
fluxbb
|
fluxbb
|
Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user login form. When a long password is sent, the password hashing process will res…
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2020-28873
|
2024-11-21 14:23 |
2021-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199449
|
9.1 |
CRITICAL
Network
|
zyxel
|
lte4506-m606_firmware lte7460-m608_firmware wah7706_firmware
|
The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to u…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-28899
|
2024-11-21 14:23 |
2021-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199450
|
9.8 |
CRITICAL
Network
|
fivestarplugins
|
five_star_restaurant_menu
|
The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in inc…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-29045
|
2024-11-21 14:23 |
2021-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|