|
200211
|
8.1 |
HIGH
Network
|
netapp debian oracle fasterxml
|
service_level_manager debian_linux webcenter_portal primavera_unifier application_testing_suite agile_plm communications_policy_management communications_billing_and_revenue_mana…
|
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-36181
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200212
|
9.8 |
CRITICAL
Network
|
tp-link
|
tl-wr840n_firmware
|
oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web interface (an IP address field) is used directly for…
|
CWE-78
OS Command
|
CVE-2020-36178
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200213
|
9.8 |
CRITICAL
Network
|
wolfssl
|
wolfssl
|
RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certain relationships between key size and digest size.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-36177
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200214
|
7.5 |
HIGH
Network
|
ithemes
|
ithemes_security
|
The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.
|
CWE-287
Improper Authentication
|
CVE-2020-36176
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200215
|
5.3 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms
|
The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.
|
CWE-20
Improper Input Validation
|
CVE-2020-36175
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200216
|
6.5 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms
|
The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.
|
CWE-352
Origin Validation Error
|
CVE-2020-36174
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200217
|
5.3 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms
|
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2020-36173
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200218
|
6.1 |
MEDIUM
Network
|
advancedcustomfields
|
advanced_custom_fields
|
The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-36172
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200219
|
6.1 |
MEDIUM
Network
|
elementor
|
website_builder
|
The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.
|
CWE-79
Cross-site Scripting
|
CVE-2020-36171
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200220
|
5.3 |
MEDIUM
Network
|
ultimatemember
|
ultimate_member
|
The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms.
|
NVD-CWE-noinfo
|
CVE-2020-36170
|
2024-11-21 14:28 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|