|
197761
|
7.5 |
HIGH
Network
|
sharp
|
aquos_sh-m02_firmware aquos_sh-rm02_firmware aquos_mini_sh-m03_firmware aquos_l2_firmware aquos_sense_lite_sh-m05_firmware aquos_sense_firmware aquos_compact_sh-m06_firmware aquo…
|
SHARP AQUOS series (AQUOS SH-M02 build number 01.00.05 and earlier, AQUOS SH-RM02 build number 01.00.04 and earlier, AQUOS mini SH-M03 build number 01.00.04 and earlier, AQUOS Keitai SH-N01 build num…
|
CWE-200
Information Exposure
|
CVE-2020-5571
|
2024-11-21 14:34 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197762
|
7.8 |
HIGH
Local
|
plex
|
media_server
|
Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYSTEM privileges.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-5740
|
2024-11-21 14:34 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197763
|
8.4 |
HIGH
Local
|
toshiba
|
password_tool_for_windows
|
An unquoted search path vulnerability exists in HDD Password tool (for Windows) version 1.20.6620 and earlier which is stored in CANVIO PREMIUM 3TB(HD-MB30TY, HD-MA30TY, HD-MB30TS, HD-MA30TS), CANVIO…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2020-5569
|
2024-11-21 14:34 |
2020-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197764
|
5.4 |
MEDIUM
Network
|
tenable
|
tenable.sc
|
Stored XSS in Tenable.Sc before 5.14.0 could allow an authenticated remote attacker to craft a request to execute arbitrary script code in a user's browser session. Updated input validation technique…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5737
|
2024-11-21 14:34 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197765
|
6.1 |
MEDIUM
Network
|
openmrs
|
openmrs
|
In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it. This allows the export of…
|
CWE-601
Open Redirect
|
CVE-2020-5733
|
2024-11-21 14:34 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197766
|
6.1 |
MEDIUM
Network
|
openmrs
|
openmrs
|
In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it. This allows unauthenticate…
|
CWE-601
Open Redirect
|
CVE-2020-5732
|
2024-11-21 14:34 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197767
|
6.1 |
MEDIUM
Network
|
openmrs
|
openmrs
|
In OpenMRS 2.9 and prior, the app parameter for the ActiveVisit's page is vulnerable to cross-site scripting.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5731
|
2024-11-21 14:34 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197768
|
6.1 |
MEDIUM
Network
|
openmrs
|
openmrs
|
In OpenMRS 2.9 and prior, the sessionLocation parameter for the login page is vulnerable to cross-site scripting.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5730
|
2024-11-21 14:34 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197769
|
6.1 |
MEDIUM
Network
|
openmrs
|
openmrs
|
In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which can result in XSS. Any page that is able to trigger a UI Framework Error is su…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5729
|
2024-11-21 14:34 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197770
|
6.1 |
MEDIUM
Network
|
openmrs
|
openmrs
|
OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (such as login.htm). There is insufficient validation for this parameter, which all…
|
CWE-79 CWE-20
Cross-site Scripting Improper Input Validation
|
CVE-2020-5728
|
2024-11-21 14:34 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|