|
196881
|
6.1 |
MEDIUM
Network
|
dolibarr
|
dolibarr_erp\/crm
|
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 10.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) label[libelle] parameter to the /htdocs/admin/dict.php…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7994
|
2024-11-21 14:38 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196882
|
8.8 |
HIGH
Network
|
adive
|
framework
|
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
|
CWE-352
Origin Validation Error
|
CVE-2020-7991
|
2024-11-21 14:38 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196883
|
6.1 |
MEDIUM
Network
|
adive
|
framework
|
Adive Framework 2.0.8 has admin/user/add userName XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7990
|
2024-11-21 14:38 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196884
|
6.1 |
MEDIUM
Network
|
adive
|
framework
|
Adive Framework 2.0.8 has admin/user/add userUsername XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7989
|
2024-11-21 14:38 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196885
|
7.5 |
HIGH
Network
|
solarwinds
|
n-central
|
SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive inf…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-7984
|
2024-11-21 14:38 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196886
|
9.8 |
CRITICAL
Network
|
rubygeocoder
|
geocoder
|
sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data.
|
CWE-89
SQL Injection
|
CVE-2020-7981
|
2024-11-21 14:38 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196887
|
9.8 |
CRITICAL
Network
|
intelliantech
|
aptus_web
|
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. NOTE: a valid sid cookie for a login to the intelli…
|
CWE-78
OS Command
|
CVE-2020-7980
|
2024-11-21 14:38 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196888
|
5.3 |
MEDIUM
Network
|
mirumee
|
saleor
|
An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user ID and consequently…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-7964
|
2024-11-21 14:38 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196889
|
9.8 |
CRITICAL
Network
|
plone
|
plone
|
A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission.
|
NVD-CWE-noinfo
|
CVE-2020-7941
|
2024-11-21 14:38 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196890
|
7.5 |
HIGH
Network
|
plone
|
plone
|
Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.
|
CWE-521
Weak Password Requirements
|
CVE-2020-7940
|
2024-11-21 14:38 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|