|
198411
|
6.1 |
MEDIUM
Network
|
ec-cube
|
ec-cube
|
Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking attacks. If a user accesses a specially crafted page while logged into the administ…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-5679
|
2024-11-21 14:34 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198412
|
6.1 |
MEDIUM
Network
|
weseek
|
growi
|
Stored cross-site scripting vulnerability in GROWI v3.8.1 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5678
|
2024-11-21 14:34 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198413
|
6.1 |
MEDIUM
Network
|
weseek
|
growi
|
Reflected cross-site scripting vulnerability in GROWI v4.0.0 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5677
|
2024-11-21 14:34 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198414
|
7.5 |
HIGH
Network
|
weseek
|
growi
|
GROWI v4.1.3 and earlier allow remote attackers to obtain information which is not allowed to access via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2020-5676
|
2024-11-21 14:34 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198415
|
6.1 |
MEDIUM
Network
|
desknets
|
neo
|
Cross-site scripting vulnerability in desknet's NEO (desknet's NEO Small License V5.5 R1.5 and earlier, and desknet's NEO Enterprise License V5.5 R1.5 and earlier) allows remote attackers to inject a…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5638
|
2024-11-21 14:34 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198416
|
7.5 |
HIGH
Network
|
cloudfoundry
|
cf-deployment capi-release
|
CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can send specially-crafted YAML files to certain endpoint…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-5423
|
2024-11-21 14:34 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198417
|
9.8 |
CRITICAL
Network
|
valvesoftware
|
game_networking_sockets
|
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decrypt() when compiled using libsodium, leading to a Stack-Base…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6018
|
2024-11-21 14:34 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198418
|
6.5 |
MEDIUM
Network
|
netgear
|
gs108ev3_firmware
|
Cross-site request forgery (CSRF) vulnerability in GS108Ev3 firmware version 2.06.10 and earlier allows remote attackers to hijack the authentication of administrators and the product's settings may …
|
CWE-352
Origin Validation Error
|
CVE-2020-5641
|
2024-11-21 14:34 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198419
|
7.8 |
HIGH
Local
|
epson
|
remote_printer_driver connect scanner_driver net_software_development_kit net_print net_config_se net_config scan_icm_updater e-photo easy_photo_print prolab_print im…
|
Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-5674
|
2024-11-21 14:34 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198420
|
6.1 |
MEDIUM
Physics
|
tp-link
|
archer_c9_firmware
|
UNIX Symbolic Link (Symlink) Following in TP-Link Archer C9(US)_V1_180125 firmware allows an unauthenticated actor, with physical access and network access, to read sensitive files and write to a lim…
|
CWE-59
Link Following
|
CVE-2020-5797
|
2024-11-21 14:34 |
2020-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|