|
196811
|
5.4 |
MEDIUM
Network
|
nagios
|
nagios
|
Nagios Log Server 2.1.3 allows XSS by visiting /profile and entering a crafted name field that is mishandled on the /admin/users page. Any malicious user with limited access can store an XSS payload …
|
CWE-79
Cross-site Scripting
|
CVE-2020-6586
|
2024-11-21 14:36 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196812
|
8.8 |
HIGH
Network
|
nagios
|
nagios
|
Nagios Log Server 2.1.3 has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-6585
|
2024-11-21 14:36 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196813
|
6.5 |
MEDIUM
Network
|
nagios
|
nagios
|
Nagios Log Server 2.1.3 has Incorrect Access Control.
|
CWE-269
Improper Privilege Management
|
CVE-2020-6584
|
2024-11-21 14:36 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196814
|
9.8 |
CRITICAL
Network
|
rockwellautomation
|
micrologix_1400_a_firmware micrologix_1400_b_firmware micrologix_1100_firmware rslogix_500
|
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-6990
|
2024-11-21 14:36 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196815
|
7.5 |
HIGH
Network
|
rockwellautomation
|
micrologix_1400_a_firmware micrologix_1400_b_firmware micrologix_1100_firmware rslogix_500
|
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, A remote, unauthe…
|
CWE-287
Improper Authentication
|
CVE-2020-6988
|
2024-11-21 14:36 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196816
|
3.3 |
LOW
Local
|
rockwellautomation
|
micrologix_1400_a_firmware micrologix_1400_b_firmware micrologix_1100_firmware rslogix_500
|
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, If Simple Mail Tr…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-6980
|
2024-11-21 14:36 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196817
|
5.4 |
MEDIUM
Network
|
fortinet
|
fortiisolator
|
An improper neutralization of input vulnerability in the URL Description in Fortinet FortiIsolator version 1.2.2 allows a remote authenticated attacker to perform a cross site scripting attack (XSS).
|
CWE-79
Cross-site Scripting
|
CVE-2020-6643
|
2024-11-21 14:36 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196818
|
6.5 |
MEDIUM
Network
|
hotels
|
styx
|
Hotels Styx through 1.0.0.beta8 allows HTTP response splitting due to CRLF Injection. This is exploitable if untrusted user input can appear in a response header.
|
CWE-74
Injection
|
CVE-2020-6858
|
2024-11-21 14:36 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196819
|
7.8 |
HIGH
Local
|
mcafee
|
advanced_threat_defense
|
Privilege Escalation vulnerability in the command line interface in McAfee Advanced Threat Defense (ATD) 4.x prior to 4.8.2 allows local users to execute arbitrary code via improper access controls o…
|
CWE-269
Improper Privilege Management
|
CVE-2020-7254
|
2024-11-21 14:36 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196820
|
4.4 |
MEDIUM
Local
|
mcafee
|
agent
|
Improper access control vulnerability in masvc.exe in McAfee Agent (MA) prior to 5.6.4 allows local users with administrator privileges to disable self-protection via a McAfee supplied command-line u…
|
CWE-20
Improper Input Validation
|
CVE-2020-7253
|
2024-11-21 14:36 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|