|
210221
|
6.5 |
MEDIUM
Network
|
gogogate
|
ismartgate_pro_firmware
|
iSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to create a new user via /index.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-12281
|
2024-11-21 13:59 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210222
|
6.5 |
MEDIUM
Network
|
gogogate
|
ismartgate_pro_firmware
|
iSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to open/close a specified garage door/gate via /isg/opendoor.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-12280
|
2024-11-21 13:59 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210223
|
7.2 |
HIGH
Network
|
apache
|
syncope
|
In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow entitlements can use Shell Service Tasks to perform malicious operations, inclu…
|
NVD-CWE-noinfo
|
CVE-2020-11977
|
2024-11-21 13:59 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210224
|
7.5 |
HIGH
Network
|
apache
|
cocoon
|
When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.
|
CWE-611
XXE
|
CVE-2020-11991
|
2024-11-21 13:59 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210225
|
9.8 |
CRITICAL
Network
|
apache oracle
|
activemq flexcube_private_banking enterprise_repository communications_diameter_signaling_router communications_element_manager communications_session_route_manager communications_s…
|
A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it l…
|
NVD-CWE-noinfo
|
CVE-2020-11998
|
2024-11-21 13:59 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210226
|
9.8 |
CRITICAL
Network
|
apache
|
netbeans
|
To be able to analyze gradle projects, the build scripts need to be executed. Apache NetBeans follows this pattern. This causes the code of the build script to be invoked at load time of the project.…
|
NVD-CWE-noinfo
|
CVE-2020-11986
|
2024-11-21 13:59 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210227
|
8.8 |
HIGH
Network
|
foxitsoftware
|
phantompdf reader
|
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can execute arbitrary code via a heap-based buffer overflow because dirty image-resource data is mishandled.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12248
|
2024-11-21 13:59 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210228
|
7.1 |
HIGH
Local
|
foxitsoftware
|
phantompdf reader
|
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information from an out-of-bounds read because a text-string index continues to be used after…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-12247
|
2024-11-21 13:59 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210229
|
6.1 |
MEDIUM
Network
|
oscommerce
|
ce_phoenix
|
Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page paramete…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12058
|
2024-11-21 13:59 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210230
|
6.1 |
MEDIUM
Physics
|
teamwire
|
teamwire
|
The Teamwire application 5.3.0 for Android allows physically proximate attackers to exploit a flaw related to the pass-code component.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-12621
|
2024-11-21 13:59 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|