|
198111
|
7.5 |
HIGH
Network
|
linksys
|
re6500_firmware
|
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to cause a persistent denial of service (segmentation fault) via a long /goform/langSwitch langSelectionOnly parameter.
|
NVD-CWE-noinfo
|
CVE-2020-35716
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198112
|
8.8 |
HIGH
Network
|
linksys
|
re6500_firmware
|
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote authenticated users to execute arbitrary commands via shell metacharacters in a filename to the upload_settings.cgi page.
|
CWE-78
OS Command
|
CVE-2020-35715
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198113
|
8.8 |
HIGH
Network
|
linksys
|
re6500_firmware
|
Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in conjunction with the goform/pingstart program.
|
CWE-78
OS Command
|
CVE-2020-35714
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198114
|
9.8 |
CRITICAL
Network
|
linksys
|
re6500_firmware
|
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters to the goform/setSysAdm page.
|
CWE-78
OS Command
|
CVE-2020-35713
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198115
|
9.8 |
CRITICAL
Network
|
esri
|
arcgis_server
|
Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-35712
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198116
|
7.5 |
HIGH
Network
|
arc-swap_project
|
arc-swap
|
An issue has been discovered in the arc-swap crate before 0.4.8 (and 1.x before 1.1.0) for Rust. Use of arc_swap::access::Map with the Constant test helper (or with a user-supplied implementation of …
|
NVD-CWE-noinfo
|
CVE-2020-35711
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198117
|
5.3 |
MEDIUM
Network
|
parallels
|
remote_application_server
|
Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submission of the login form (even with blank credentials) provides this address to the…
|
CWE-200
Information Exposure
|
CVE-2020-35710
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198118
|
4.9 |
MEDIUM
Network
|
bloofox
|
bloofoxcms
|
bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../media/images/ via the admin/index.php?mode=tools&page=upload URI, aka directory t…
|
CWE-22
Path Traversal
|
CVE-2020-35709
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198119
|
7.2 |
HIGH
Network
|
phplist
|
phplist
|
phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Administrators" page.
|
CWE-89
SQL Injection
|
CVE-2020-35708
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198120
|
5.4 |
MEDIUM
Network
|
daybydaycrm
|
daybyday
|
Daybyday 2.1.0 allows stored XSS via the Company Name parameter to the New Client screen.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35707
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|