|
210471
|
9.8 |
CRITICAL
Network
|
nanometrics
|
titansma centaur
|
Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2020-12134
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210472
|
6.1 |
MEDIUM
Network
|
fifthplay
|
s.a.m.i
|
Fifthplay S.A.M.I before 2019.3_HP2 allows unauthenticated stored XSS via a POST request.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12132
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210473
|
6.1 |
MEDIUM
Network
|
app2pro
|
airdisk_pro
|
The AirDisk Pro app 5.5.3 for iOS allows XSS via the devicename parameter (shown next to the UI logo).
|
CWE-79
Cross-site Scripting
|
CVE-2020-12131
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210474
|
5.3 |
MEDIUM
Network
|
postfix
|
postfix
|
A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demonstrated by the similarity of \xce\xbf to the 'o' character…
|
NVD-CWE-Other
|
CVE-2020-12063
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210475
|
6.1 |
MEDIUM
Network
|
app2pro
|
airdisk_pro
|
The AirDisk Pro app 5.5.3 for iOS allows XSS via the deleteFile parameter of the Delete function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12130
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210476
|
6.1 |
MEDIUM
Network
|
app2pro
|
airdisk_pro
|
The AirDisk Pro app 5.5.3 for iOS allows XSS via the createFolder parameter of the Create Folder function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12129
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210477
|
7.5 |
HIGH
Network
|
file_transfer_ifamily_project
|
file_transfer_ifamily
|
DONG JOO CHO File Transfer iFamily 2.1 allows directory traversal related to the ./etc/ path.
|
CWE-22
Path Traversal
|
CVE-2020-12128
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210478
|
8.2 |
HIGH
Network
|
binance
|
tss-lib
|
The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a signing round or obtain sensitive information fro…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-12118
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210479
|
6.1 |
MEDIUM
Network
|
bigbluebutton
|
bigbluebutton
|
BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12113
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210480
|
7.5 |
HIGH
Network
|
bigbluebutton
|
bigbluebutton
|
BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.
|
CWE-22
Path Traversal
|
CVE-2020-12112
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|