|
209621
|
6.1 |
MEDIUM
Network
|
i-doit
|
i-doit
|
A cross-site scripting (XSS) vulnerability in i-doit 1.14.2 allows remote attackers to inject arbitrary web script or HTML via the viewMode, tvMode, tvType, objID, catgID, objTypeID, or editMode para…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13825
|
2024-11-21 14:01 |
2020-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209622
|
9.0 |
CRITICAL
Network
|
securenvoy
|
securmail
|
SecurEnvoy SecurMail 9.3.503 allows attackers to upload executable files and achieve OS command execution via a crafted SecurEnvoyReply cookie.
|
CWE-22
Path Traversal
|
CVE-2020-13376
|
2024-11-21 14:01 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209623
|
9.8 |
CRITICAL
Network
|
ivanti
|
dsm_netinst
|
Unsafe storage of AD credentials in Ivanti DSM netinst 5.1 due to a static, hard-coded encryption key.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-13793
|
2024-11-21 14:01 |
2020-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209624
|
8.8 |
HIGH
Network
|
zyxel
|
nas326_firmware nas520_firmware nas540_firmware nas542_firmware
|
Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can be used for a TELNET session as root. This affects…
|
CWE-287
Improper Authentication
|
CVE-2020-13365
|
2024-11-21 14:01 |
2020-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209625
|
8.8 |
HIGH
Network
|
zyxel
|
nas326_firmware nas520_firmware nas540_firmware nas542_firmware
|
A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, …
|
NVD-CWE-noinfo
|
CVE-2020-13364
|
2024-11-21 14:01 |
2020-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209626
|
8.8 |
HIGH
Network
|
quadra-informatique
|
atos\/sips
|
The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection.
|
CWE-78
OS Command
|
CVE-2020-13404
|
2024-11-21 14:01 |
2020-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209627
|
6.1 |
MEDIUM
Network
|
extremenetworks
|
extreme_management_center
|
Extreme EAC Appliance 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13819
|
2024-11-21 14:01 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209628
|
7.1 |
HIGH
Local
|
softperfect
|
ram_disk
|
An exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can allow an unprivileged user to delete any file …
|
NVD-CWE-noinfo
|
CVE-2020-13522
|
2024-11-21 14:01 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209629
|
3.3 |
LOW
Local
|
softperfect
|
ram_disk
|
An exploitable information disclosure vulnerability exists in SoftPerfect’s RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can cause the disclosure of sensitive informati…
|
CWE-862
Missing Authorization
|
CVE-2020-13523
|
2024-11-21 14:01 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209630
|
6.1 |
MEDIUM
Network
|
extremenetworks
|
extreme_management_center
|
Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13820
|
2024-11-21 14:01 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|