|
196411
|
6.1 |
MEDIUM
Network
|
axper
|
vision_ii_firmware
|
Axper Vision II 4 devices allow XSS via the DEVICE_NAME (aka Device Name) parameter to the configWebParams.cgi URI.
|
CWE-79
Cross-site Scripting
|
CVE-2020-6848
|
2024-11-21 14:36 |
2020-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196412
|
5.4 |
MEDIUM
Network
|
opentrade_project
|
opentrade
|
OpenTrade through 0.2.0 has a DOM-based XSS vulnerability that is executed when an administrator attempts to delete a message that contains JavaScript.
|
CWE-79
Cross-site Scripting
|
CVE-2020-6847
|
2024-11-21 14:36 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196413
|
9.8 |
CRITICAL
Network
|
mruby
|
mruby
|
In mruby 2.1.0, there is a use-after-free in hash_slice in mrbgems/mruby-hash-ext/src/hash-ext.c.
|
CWE-416
Use After Free
|
CVE-2020-6840
|
2024-11-21 14:36 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196414
|
9.8 |
CRITICAL
Network
|
mruby
|
mruby
|
In mruby 2.1.0, there is a stack-based buffer overflow in mrb_str_len_to_dbl in string.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6839
|
2024-11-21 14:36 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196415
|
9.8 |
CRITICAL
Network
|
mruby
|
mruby
|
In mruby 2.1.0, there is a use-after-free in hash_values_at in mrbgems/mruby-hash-ext/src/hash-ext.c.
|
CWE-416
Use After Free
|
CVE-2020-6838
|
2024-11-21 14:36 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196416
|
9.8 |
CRITICAL
Network
|
hot-formula-parser_project
|
hot-formula-parser
|
grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanitize values passed to the parse function and concat…
|
CWE-94
Code Injection
|
CVE-2020-6836
|
2024-11-21 14:36 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196417
|
9.8 |
CRITICAL
Network
|
bftpd_project
|
bftpd
|
An issue was discovered in Bftpd before 5.4. There is a heap-based off-by-one error during file-transfer error checking.
|
CWE-193
Off-by-one Error
|
CVE-2020-6835
|
2024-11-21 14:36 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196418
|
6.1 |
MEDIUM
Network
|
rasilient
|
pixelstor_5000_firmware
|
A cross-site scripting (XSS) vulnerability in Option/optionsAll.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows remote attackers to inject arbitrary web script or HTML via th…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6758
|
2024-11-21 14:36 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196419
|
8.8 |
HIGH
Network
|
rasilient
|
pixelstor_5000_firmware
|
contentHostProperties.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows authenticated attackers to remotely execute code via the name parameter.
|
CWE-78
OS Command
|
CVE-2020-6757
|
2024-11-21 14:36 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196420
|
9.8 |
CRITICAL
Network
|
rasilient
|
pixelstor_5000_firmware
|
languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the lang parameter.
|
CWE-78
OS Command
|
CVE-2020-6756
|
2024-11-21 14:36 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|