|
200541
|
7.2 |
HIGH
Network
|
qnap
|
qes
|
A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-2499
|
2024-11-21 14:25 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200542
|
6.1 |
MEDIUM
Network
|
qnap
|
quts_hero qts
|
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in certificate configuration. QANP have already fixed these vulnerabilities in the followin…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2498
|
2024-11-21 14:25 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200543
|
6.1 |
MEDIUM
Network
|
qnap
|
music_station
|
This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in the following versions of Music Station. QuTS …
|
CWE-79
Cross-site Scripting
|
CVE-2020-2494
|
2024-11-21 14:25 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200544
|
6.1 |
MEDIUM
Network
|
qnap
|
multimedia_console
|
This cross-site scripting vulnerability in Multimedia Console allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in Multimedia Console 1.1.5 and later.
|
CWE-79
Cross-site Scripting
|
CVE-2020-2493
|
2024-11-21 14:25 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200545
|
6.1 |
MEDIUM
Network
|
qnap
|
photo_station
|
This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. QT…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2491
|
2024-11-21 14:25 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200546
|
6.1 |
MEDIUM
Network
|
qnap
|
quts_hero qts
|
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Connection Logs. QANP have already fixed these vulnerabilities in the following v…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2497
|
2024-11-21 14:25 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200547
|
6.1 |
MEDIUM
Network
|
qnap
|
quts_hero qts
|
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2496
|
2024-11-21 14:25 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200548
|
6.1 |
MEDIUM
Network
|
qnap
|
quts_hero qts
|
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2495
|
2024-11-21 14:25 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200549
|
7.5 |
HIGH
Network
|
jenkins
|
cvs
|
Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
CWE-611
XXE
|
CVE-2020-2324
|
2024-11-21 14:25 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200550
|
5.3 |
MEDIUM
Network
|
netflix
|
chaos_monkey
|
Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers with Overall/Read permission to access the Chaos Monkey page and to see the hist…
|
CWE-862
Missing Authorization
|
CVE-2020-2323
|
2024-11-21 14:25 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|