|
196811
|
7.5 |
HIGH
Network
|
wpseeds
|
wp_database_backup
|
The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/uploads/db-backup/. This might allow attackers to read ZIP archives by guessing…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-7241
|
2024-11-21 14:36 |
2020-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196812
|
5.5 |
MEDIUM
Local
|
gallagher
|
command_centre
|
An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4). External system configuration data (used for third party inte…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-7215
|
2024-11-21 14:36 |
2020-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196813
|
8.8 |
HIGH
Network
|
cacti
|
cacti
|
Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php. OS commands are executed when a new poller c…
|
CWE-78
OS Command
|
CVE-2020-7237
|
2024-11-21 14:36 |
2020-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196814
|
6.1 |
MEDIUM
Network
|
uhp
|
uhp-100_firmware
|
UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cw2?td= (Site Name field of the Site Setup section).
|
CWE-79
Cross-site Scripting
|
CVE-2020-7236
|
2024-11-21 14:36 |
2020-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196815
|
6.1 |
MEDIUM
Network
|
uhp
|
uhp-100_firmware
|
UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cB3?ta= (profile title).
|
CWE-79
Cross-site Scripting
|
CVE-2020-7235
|
2024-11-21 14:36 |
2020-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196816
|
4.8 |
MEDIUM
Network
|
ruckuswireless
|
r310_firmware
|
Ruckus ZoneFlex R310 104.0.0.0.1347 devices allow Stored XSS via the SSID field on the Configuration > Radio 2.4G > Wireless X screen (after a successful login to the super account).
|
CWE-79
Cross-site Scripting
|
CVE-2020-7234
|
2024-11-21 14:36 |
2020-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196817
|
9.8 |
CRITICAL
Network
|
kmccontrols
|
bac-a1616bc_firmware
|
KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Logon.swf file.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-7233
|
2024-11-21 14:36 |
2020-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196818
|
7.5 |
HIGH
Network
|
evoko
|
home
|
Evoko Home devices 1.31 through 1.37 allow remote attackers to obtain sensitive information (such as usernames and password hashes) via a WebSocket request, as demonstrated by the sockjs/224/uf1psgff…
|
NVD-CWE-noinfo
|
CVE-2020-7232
|
2024-11-21 14:36 |
2020-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196819
|
5.3 |
MEDIUM
Network
|
evoko
|
home
|
Evoko Home 1.31 devices provide different error messages for failed login requests depending on whether the username is valid.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-7231
|
2024-11-21 14:36 |
2020-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196820
|
6.5 |
MEDIUM
Network
|
westermo
|
mrd-315_firmware
|
Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web applic…
|
NVD-CWE-noinfo
|
CVE-2020-7227
|
2024-11-21 14:36 |
2020-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|