|
197301
|
6.1 |
MEDIUM
Network
|
zen-cart
|
zen_cart
|
Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_page.php or includes/templates/responsive_classic/common/tpl_main_page.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-6578
|
2024-11-21 14:35 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197302
|
9.8 |
CRITICAL
Network
|
it-recht-kanzlei
|
it-recht-kanzlei
|
The IT-Recht Kanzlei plugin in Zen Cart 1.5.6c (German edition) allows itrk-api.php rechtstext_language SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2020-6577
|
2024-11-21 14:35 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197303
|
7.5 |
HIGH
Network
|
rockwellautomation
|
flex_io_1794-aent\/b_firmware
|
An exploitable denial of service vulnerability exists in the ENIP Request Path Network Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.003. A specially crafted network request can cause …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-6088
|
2024-11-21 14:35 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197304
|
7.8 |
HIGH
Local
|
checkpoint
|
smartconsole
|
Check Point SmartConsole before R80.10 Build 185, R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vulnerable to a possible local privilege escalation …
|
CWE-269
Improper Privilege Management
|
CVE-2020-6024
|
2024-11-21 14:35 |
2021-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197305
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2020-6572
|
2024-11-21 14:35 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197306
|
6.1 |
MEDIUM
Network
|
opera
|
opera
|
URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scripting (XSS) attacks, but in certain circumstances this removal was not perform…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6159
|
2024-11-21 14:35 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197307
|
7.5 |
HIGH
Network
|
rockwellautomation
|
micrologix_1100_b_firmware
|
An exploitable denial-of-service vulnerability exists in the IPv4 functionality of Allen-Bradley MicroLogix 1100 Programmable Logic Controller Systems Series B FRN 16.000, Series B FRN 15.002, Series…
|
NVD-CWE-noinfo
|
CVE-2020-6111
|
2024-11-21 14:35 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197308
|
3.5 |
LOW
Adjacent
|
sap
|
adaptive_server_enterprise
|
In certain situations, an attacker with regular user credentials and local access to an ASE cockpit installation can access sensitive information which appears in the installation log files. This inf…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-6317
|
2024-11-21 14:35 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197309
|
4.3 |
MEDIUM
Network
|
opera
|
opera_touch
|
Opera Touch for iOS before version 2.4.5 is vulnerable to an address bar spoofing attack. The vulnerability allows a malicious page to trick the browser into showing an address of a different page. T…
|
NVD-CWE-Other
|
CVE-2020-6157
|
2024-11-21 14:35 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197310
|
7.8 |
HIGH
Local
|
pixar
|
openusd
|
A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. To trigger this vulnerability, the victim needs to open an attacker-provi…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6156
|
2024-11-21 14:35 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|