|
198421
|
5.4 |
MEDIUM
Network
|
quest
|
policy_authority_for_unified_communications
|
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the ReportPreview.do file via the referer parameter…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35723
|
2024-11-21 14:27 |
2021-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198422
|
6.5 |
MEDIUM
Network
|
quest
|
policy_authority_for_unified_communications
|
CSRF in Web Compliance Manager in Quest Policy Authority 8.1.2.200 allows remote attackers to force user modification/creation via a specially crafted link to the submitUser.jsp file. NOTE: This vuln…
|
CWE-352
Origin Validation Error
|
CVE-2020-35722
|
2024-11-21 14:27 |
2021-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198423
|
5.4 |
MEDIUM
Network
|
quest
|
policy_authority_for_unified_communications
|
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the BrowseAssets.do file via the title parameter. N…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35721
|
2024-11-21 14:27 |
2021-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198424
|
5.4 |
MEDIUM
Network
|
quest
|
policy_authority_for_unified_communications
|
Stored XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to store malicious code in multiple fields (first name, last name, and logon name) when creating or modifying a user via the sub…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35720
|
2024-11-21 14:27 |
2021-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198425
|
6.1 |
MEDIUM
Network
|
quest
|
policy_authority_for_unified_communications
|
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/Applications/Search/index.jsp file via t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35719
|
2024-11-21 14:27 |
2021-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198426
|
8.8 |
HIGH
Network
|
phpgurukul
|
hospital_management_system
|
PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get…
|
CWE-862
Missing Authorization
|
CVE-2020-35745
|
2024-11-21 14:27 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198427
|
6.1 |
MEDIUM
Network
|
digisol
|
dg-hr3400_firmware
|
Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date module and "Keyword" in URL Filter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35262
|
2024-11-21 14:27 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198428
|
7.5 |
HIGH
Network
|
nxlog
|
nxlog
|
The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a crafted Syslog payload to the Syslog service. Thi…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-35488
|
2024-11-21 14:27 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198429
|
9.8 |
CRITICAL
Network
|
asus
|
dsl-n17u_firmware
|
The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication via a POST request to Advanced_System_Content.asp wi…
|
CWE-287
Improper Authentication
|
CVE-2020-35219
|
2024-11-21 14:27 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198430
|
5.5 |
MEDIUM
Local
|
gnu redhat netapp broadcom
|
binutils enterprise_linux hci_compute_node_firmware cloud_backup ontap_select_deploy_administration_utility solidfire_\&_hci_management_node solidfire\ _enterprise_sds_\&…
|
There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to caus…
|
-
|
CVE-2020-35507
|
2024-11-21 14:27 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|