|
196861
|
9.8 |
CRITICAL
Network
|
prosody debian
|
mod_auth_ldap2 mod_auth_ldap debian_linux
|
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only fu…
|
CWE-863
Incorrect Authorization
|
CVE-2020-8086
|
2024-11-21 14:38 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196862
|
5.4 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue. Any user can modify…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7934
|
2024-11-21 14:38 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196863
|
8.8 |
HIGH
Network
|
super_file_explorer_project
|
super_file_explorer
|
An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the r…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-7998
|
2024-11-21 14:38 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196864
|
6.1 |
MEDIUM
Network
|
asus
|
rt-ac66u_firmware
|
ASUS WRT-AC66U 3 RT 3.0.0.4.372_67 devices allow XSS via the Client Name field to the Parental Control feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7997
|
2024-11-21 14:38 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196865
|
6.1 |
MEDIUM
Network
|
typo3
|
typo3
|
svg.swf in TYPO3 6.2.0 to 6.2.38 ELTS and 7.0.0 to 7.1.0 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system. This may be at a contrib/…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8091
|
2024-11-21 14:38 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196866
|
4.8 |
MEDIUM
Network
|
a1
|
wlan_box_adb_vv2220_firmware
|
The Username field in the Storage Service settings of A1 WLAN Box ADB VV2220v2 devices allows stored XSS (after a successful Administrator login).
|
CWE-79
Cross-site Scripting
|
CVE-2020-8090
|
2024-11-21 14:38 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196867
|
9.8 |
CRITICAL
Network
|
usebb
|
usebb
|
panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password hashes, which mishandles hashes that begin with 0e followed by exclusively numeric…
|
NVD-CWE-noinfo
|
CVE-2020-8088
|
2024-11-21 14:38 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196868
|
9.8 |
CRITICAL
Network
|
smc
|
d3g0804w_firmware
|
SMC Networks D3G0804W D3GNV5M-3.5.1.6.10_GA devices allow remote command execution by leveraging access to the Network Diagnostic Tools screen, as demonstrated by an admin login. The attacker must us…
|
CWE-20
Improper Input Validation
|
CVE-2020-8087
|
2024-11-21 14:38 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196869
|
7.8 |
HIGH
Local
|
valvesoftware
|
dota_2
|
rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a cra…
|
NVD-CWE-noinfo
|
CVE-2020-7952
|
2024-11-21 14:38 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196870
|
7.8 |
HIGH
Local
|
valvesoftware
|
dota_2
|
meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7951
|
2024-11-21 14:38 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|