|
210171
|
6.1 |
MEDIUM
Network
|
naviwebs
|
navigate_cms
|
An issue was discovered in Navigate CMS 2.9 r1433. There is a stored XSS vulnerability that is executed on the page to view users, and on the page to edit users. This is present in both the User fiel…
|
CWE-79
Cross-site Scripting
|
CVE-2020-14018
|
2024-11-21 14:02 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210172
|
7.5 |
HIGH
Network
|
naviwebs
|
navigate_cms
|
An issue was discovered in Navigate CMS 2.9 r1433. Sessions, as well as associated information such as CSRF tokens, are stored in cleartext files in the directory /private/sessions. An unauthenticate…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-14017
|
2024-11-21 14:02 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210173
|
5.3 |
MEDIUM
Network
|
naviwebs
|
navigate_cms
|
An issue was discovered in Navigate CMS 2.9 r1433. The forgot-password feature allows users to reset their passwords by using either their username or the email address associated with their account.…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2020-14016
|
2024-11-21 14:02 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210174
|
7.5 |
HIGH
Network
|
naviwebs
|
navigate_cms
|
An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset their password. There is, however, a flaw when no a…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2020-14015
|
2024-11-21 14:02 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210175
|
5.4 |
MEDIUM
Network
|
naviwebs
|
navigate_cms
|
An issue was discovered in Navigate CMS 2.8 and 2.9 r1433. The query parameter fid on the resource navigate.php does not perform sufficient data validation and/or encoding, making it vulnerable to re…
|
CWE-79
Cross-site Scripting
|
CVE-2020-14014
|
2024-11-21 14:02 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210176
|
5.4 |
MEDIUM
Network
|
solarwinds
|
orion_network_performance_monitor orion_web_performance_monitor
|
Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a name of an alert definition.
|
CWE-79
Cross-site Scripting
|
CVE-2020-14007
|
2024-11-21 14:02 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210177
|
5.4 |
MEDIUM
Network
|
solarwinds
|
orion_network_performance_monitor orion_web_performance_monitor
|
Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a Responsible Team.
|
CWE-79
Cross-site Scripting
|
CVE-2020-14006
|
2024-11-21 14:02 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210178
|
8.8 |
HIGH
Network
|
solarwinds
|
orion_network_performance_monitor orion_web_performance_monitor
|
Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows remote attackers to execute arbitrary code via a defined event.
|
NVD-CWE-noinfo
|
CVE-2020-14005
|
2024-11-21 14:02 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210179
|
5.4 |
MEDIUM
Network
|
paessler
|
prtg_network_monitor
|
XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can create a map, and then use the Map Designer Properties screen to insert JavaScri…
|
CWE-79
Cross-site Scripting
|
CVE-2020-14073
|
2024-11-21 14:02 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210180
|
7.5 |
HIGH
Network
|
rakuten
|
viber
|
Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious website could launch Viber with arbitrary parameters, forcing a victim to send an NTLM authentication req…
|
CWE-88
Argument Injection
|
CVE-2020-14049
|
2024-11-21 14:02 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|