|
197011
|
9.8 |
CRITICAL
Network
|
ctfd
|
ctfd
|
Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arbitrary account if the username is known and emails are enabled on the CTFd inst…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2020-7245
|
2024-11-21 14:36 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197012
|
7.5 |
HIGH
Network
|
hashicorp
|
vault
|
HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount in a deleted namespace. Fixed in 1.3.2.
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2020-7220
|
2024-11-21 14:36 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197013
|
4.8 |
MEDIUM
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-83959.
|
CWE-79
Cross-site Scripting
|
CVE-2020-6843
|
2024-11-21 14:36 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197014
|
4.3 |
MEDIUM
Network
|
umbraco
|
umbraco_cms
|
Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.
|
CWE-352
Origin Validation Error
|
CVE-2020-7210
|
2024-11-21 14:36 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197015
|
9.8 |
CRITICAL
Network
|
elementor
|
website_builder
|
The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.
|
NVD-CWE-noinfo
|
CVE-2020-7109
|
2024-11-21 14:36 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197016
|
5.4 |
MEDIUM
Network
|
codepeople
|
calculated_fields_form
|
The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present in the input forms. These can be exploited by an authenticated user.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7228
|
2024-11-21 14:36 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197017
|
9.8 |
CRITICAL
Network
|
honeywell
|
maxpro_nvr_xe_firmware maxpro_nvr_se_firmware maxpro_nvr_pe_firmware mpnvrswxx_firmware hnmswvms_firmware hnmswvmslt_firmware
|
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to…
|
CWE-89
SQL Injection
|
CVE-2020-6960
|
2024-11-21 14:36 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197018
|
9.8 |
CRITICAL
Network
|
honeywell
|
maxpro_nvr_xe_firmware maxpro_nvr_se_firmware maxpro_nvr_pe_firmware mpnvrswxx_firmware hnmswvms_firmware hnmswvmslt_firmware
|
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-6959
|
2024-11-21 14:36 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197019
|
8.1 |
HIGH
Network
|
storebackup debian opensuse canonical
|
storebackup debian_linux leap backports_sle ubuntu_linux
|
storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain f…
|
CWE-59
Link Following
|
CVE-2020-7040
|
2024-11-21 14:36 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197020
|
7.5 |
HIGH
Network
|
grin
|
grin
|
Grin through 2.1.1 has Insufficient Validation.
|
CWE-20
Improper Input Validation
|
CVE-2020-6638
|
2024-11-21 14:36 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|