|
211151
|
6.5 |
MEDIUM
Network
|
redhat
|
cloudforms
|
Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right cri…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-10779
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211152
|
6.0 |
MEDIUM
Network
|
redhat
|
cloudforms
|
In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This busines…
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2020-10778
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211153
|
5.4 |
MEDIUM
Network
|
redhat
|
cloudforms
|
A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using Clou…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10777
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211154
|
4.8 |
MEDIUM
Network
|
gambio
|
gambio_gx
|
Gambio GX before 4.0.1.0 allows XSS in admin/coupon_admin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10985
|
2024-11-21 13:56 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211155
|
8.8 |
HIGH
Network
|
gambio
|
gambio_gx
|
Gambio GX before 4.0.1.0 allows admin/admin.php CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-10984
|
2024-11-21 13:56 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211156
|
4.9 |
MEDIUM
Network
|
gambio
|
gambio_gx
|
Gambio GX before 4.0.1.0 allows SQL Injection in admin/mobile.php.
|
CWE-89
SQL Injection
|
CVE-2020-10983
|
2024-11-21 13:56 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211157
|
4.9 |
MEDIUM
Network
|
gambio
|
gambio_gx
|
Gambio GX before 4.0.1.0 allows SQL Injection in admin/gv_mail.php.
|
CWE-89
SQL Injection
|
CVE-2020-10982
|
2024-11-21 13:56 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211158
|
6.5 |
MEDIUM
Adjacent
|
netgear
|
r6700_firmware
|
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit …
|
NVD-CWE-Other
|
CVE-2020-10930
|
2024-11-21 13:56 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211159
|
8.8 |
HIGH
Adjacent
|
netgear
|
r6700_firmware
|
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vul…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-10929
|
2024-11-21 13:56 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211160
|
8.4 |
HIGH
Local
|
netgear
|
r6700_firmware
|
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vul…
|
-
|
CVE-2020-10928
|
2024-11-21 13:56 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|