|
196621
|
6.1 |
MEDIUM
Network
|
sap
|
process_integration
|
PI Rest Adapter of SAP Process Integration (update provided in SAP_XIAF 7.31, 7.40, 7.50) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-6305
|
2024-11-21 14:35 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196622
|
5.4 |
MEDIUM
Network
|
sap
|
disclosure_management
|
SAP Disclosure Management, before version 10.1, does not validate user input properly in specific use cases leading to Cross-Site Scripting.
|
CWE-79
Cross-site Scripting
|
CVE-2020-6303
|
2024-11-21 14:35 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196623
|
8.8 |
HIGH
Network
|
google opensuse fedoraproject redhat debian
|
chrome leap backports_sle fedora enterprise_linux_desktop enterprise_linux_workstation debian_linux
|
Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2020-6377
|
2024-11-21 14:35 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196624
|
7.5 |
HIGH
Network
|
sap
|
netweaver_internet_communication_manager_\(kernel\) netweaver_internet_communication_manager_\(krnl32nuc\) netweaver_internet_communication_manager_\(krnl32uc\) netweaver_internet_communicat…
|
Improper input validation in SAP NetWeaver Internet Communication Manager (update provided in KRNL32NUC & KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT KRNL64NUC & KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49…
|
CWE-20
Improper Input Validation
|
CVE-2020-6304
|
2024-11-21 14:35 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196625
|
9.1 |
CRITICAL
Network
|
bftpd_project
|
bftpd
|
An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitialized value. The daemon crashes at startup in the hidegroups_init function in d…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-6162
|
2024-11-21 14:35 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196626
|
7.6 |
HIGH
Network
|
webfactoryltd
|
minimal_coming_soon_\&_maintenance_mode
|
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availa…
|
CWE-862
Missing Authorization
|
CVE-2020-6168
|
2024-11-21 14:35 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196627
|
5.4 |
MEDIUM
Network
|
webfactoryltd
|
minimal_coming_soon_\&_maintenance_mode
|
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-6166
|
2024-11-21 14:35 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196628
|
8.8 |
HIGH
Network
|
webfactoryltd
|
minimal_coming_soon_\&_maintenance_mode
|
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote …
|
CWE-352
Origin Validation Error
|
CVE-2020-6167
|
2024-11-21 14:35 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196629
|
9.8 |
CRITICAL
Network
|
genexis
|
platinum-4410_firmware
|
An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the HTML source code of the cgi-bin/index2.asp URI.
|
CWE-200 CWE-306
Information Exposure Missing Authentication for Critical Function
|
CVE-2020-6170
|
2024-11-21 14:35 |
2020-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196630
|
6.1 |
MEDIUM
Network
|
mediawiki
|
mediawiki
|
The WikibaseMediaInfo extension 1.35 for MediaWiki allows XSS because of improper template syntax within the PropertySuggestionsWidget template (in the templates/search/PropertySuggestionsWidget.must…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6163
|
2024-11-21 14:35 |
2020-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|