|
199661
|
6.5 |
MEDIUM
Network
|
adobe
|
acrobat acrobat_dc acrobat_reader acrobat_reader_dc
|
Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information exposure vulnerability, that could enable an atta…
|
CWE-200
Information Exposure
|
CVE-2020-29075
|
2024-11-21 14:23 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199662
|
5.3 |
MEDIUM
Network
|
deepnetsecurity
|
dualshield
|
DualShield 5.9.8.0821 allows username enumeration on its login form. A valid username results in prompting for the password, whereas an invalid one will produce an "unknown username" error message.
|
NVD-CWE-noinfo
|
CVE-2020-28918
|
2024-11-21 14:23 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199663
|
5.4 |
MEDIUM
Network
|
secomea
|
sitemanager_1129_firmware sitemanager_1139_firmware sitemanager_1149_firmware sitemanager_3329_firmware sitemanager_3339_firmware sitemanager_3349_firmware sitemanager_3529_firmware…
|
Cross-site Scripting (XSS) vulnerability in GUI of Secomea SiteManager could allow an attacker to cause an XSS Attack. This issue affects: Secomea SiteManager all versions prior to 9.3.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29027
|
2024-11-21 14:23 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199664
|
6.1 |
MEDIUM
Network
|
secomea
|
sitemanager_embedded
|
A vulnerability in SiteManager-Embedded (SM-E) Web server which may allow attacker to construct a URL that if visited by another application user, will cause JavaScript code supplied by the attacker …
|
CWE-79
Cross-site Scripting
|
CVE-2020-29025
|
2024-11-21 14:23 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199665
|
5.3 |
MEDIUM
Network
|
secomea
|
gatemanager_4250_firmware gatemanager_4260_firmware gatemanager_9250_firmware gatemanager_8250_firmware
|
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in (GTA) GoToAppliance of Secomea GateManager could allow an attacker to gain access to sensitive cookies. This issue affect…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-29024
|
2024-11-21 14:23 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199666
|
3.5 |
LOW
Network
|
secomea
|
gatemanager_4250_firmware gatemanager_4260_firmware gatemanager_9250_firmware gatemanager_8250_firmware
|
Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim's com…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2020-29023
|
2024-11-21 14:23 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199667
|
5.3 |
MEDIUM
Network
|
secomea
|
gatemanager_4250_firmware gatemanager_4260_firmware gatemanager_9250_firmware gatemanager_8250_firmware
|
Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager all versions prior…
|
NVD-CWE-noinfo
|
CVE-2020-29022
|
2024-11-21 14:23 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199668
|
7.2 |
HIGH
Network
|
open-emr
|
openemr
|
A SQL injection vulnerability in interface/reports/non_reported.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the form_code parameter.
|
CWE-89
SQL Injection
|
CVE-2020-29143
|
2024-11-21 14:23 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199669
|
7.2 |
HIGH
Network
|
open-emr
|
openemr
|
A SQL injection vulnerability in interface/reports/immunization_report.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the form_code paramet…
|
CWE-89
SQL Injection
|
CVE-2020-29140
|
2024-11-21 14:23 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199670
|
7.2 |
HIGH
Network
|
open-emr
|
openemr
|
A SQL injection vulnerability in interface/main/finder/patient_select.php from library/patient.inc in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands v…
|
CWE-89
SQL Injection
|
CVE-2020-29139
|
2024-11-21 14:23 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|