|
210761
|
9.8 |
CRITICAL
Network
|
phpgurukul
|
online_book_store
|
An unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to up…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-10224
|
2024-11-21 13:55 |
2020-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210762
|
6.1 |
MEDIUM
Network
|
searchblox
|
searchblox
|
SearchBlox before Version 9.1 is vulnerable to cross-origin resource sharing misconfiguration.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10132
|
2024-11-21 13:54 |
2023-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210763
|
9.8 |
CRITICAL
Network
|
searchblox
|
searchblox
|
SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-10131
|
2024-11-21 13:54 |
2023-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210764
|
8.8 |
HIGH
Network
|
searchblox
|
searchblox
|
SearchBlox before Version 9.1 is vulnerable to business logic bypass where the user is able to create multiple super admin users in the system.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-10130
|
2024-11-21 13:54 |
2023-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210765
|
8.8 |
HIGH
Network
|
searchblox
|
searchblox
|
SearchBlox before Version 9.2.1 is vulnerable to Privileged Escalation-Lower user is able to access Admin functionality.
|
CWE-269
Improper Privilege Management
|
CVE-2020-10129
|
2024-11-21 13:54 |
2023-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210766
|
5.4 |
MEDIUM
Network
|
searchblox
|
searchblox
|
SearchBlox product with version before 9.2.1 is vulnerable to stored cross-site scripting at multiple user input parameters. In SearchBlox products multiple parameters are not sanitized/validate prop…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10128
|
2024-11-21 13:54 |
2023-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210767
|
6.5 |
MEDIUM
Adjacent
|
silabs
|
uzb-7 700_series_firmware
|
Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN_RANGE frames, allowing a remote, unauthenticated attacker to inject a FIND_NOD…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-10137
|
2024-11-21 13:54 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210768
|
5.5 |
MEDIUM
Local
|
siemens
|
simatic_rtls_locating_manager
|
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application does not properly handle the import of large configuration files. A local attacke…
|
NVD-CWE-noinfo
|
CVE-2020-10054
|
2024-11-21 13:54 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210769
|
5.5 |
MEDIUM
Local
|
siemens
|
simatic_rtls_locating_manager
|
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application writes sensitive data, such as database credentials in configuration files. A loc…
|
-
|
CVE-2020-10053
|
2024-11-21 13:54 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210770
|
5.5 |
MEDIUM
Local
|
siemens
|
simatic_rtls_locating_manager
|
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application writes sensitive data, such as usernames and passwords in log files. A local atta…
|
-
|
CVE-2020-10052
|
2024-11-21 13:54 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|