|
210611
|
6.5 |
MEDIUM
Network
|
iball
|
wrb303n_firmware
|
iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP addresses.
|
CWE-352
Origin Validation Error
|
CVE-2020-15043
|
2024-11-21 14:04 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210612
|
5.5 |
MEDIUM
Local
|
jiangmin
|
jiangmin_antivirus
|
In Jiangmin Antivirus 16.0.13.129, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values f…
|
CWE-20
Improper Input Validation
|
CVE-2020-14955
|
2024-11-21 14:04 |
2020-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210613
|
6.1 |
MEDIUM
Network
|
nedi
|
nedi
|
NeDi 1.9C is vulnerable to reflected cross-site scripting. The Devices-Config.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in …
|
CWE-79
Cross-site Scripting
|
CVE-2020-15017
|
2024-11-21 14:04 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210614
|
6.1 |
MEDIUM
Network
|
nedi
|
nedi
|
NeDi 1.9C is vulnerable to reflected cross-site scripting. The Other-Converter.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15016
|
2024-11-21 14:04 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210615
|
5.9 |
MEDIUM
Network
|
trojita_project
|
trojita
|
MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to spoof SMTP servers.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-15047
|
2024-11-21 14:04 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210616
|
8.8 |
HIGH
Network
|
supermicro
|
x10drh-it_bios x10drh-it_firmware
|
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed ver…
|
CWE-352
Origin Validation Error
|
CVE-2020-15046
|
2024-11-21 14:04 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210617
|
3.1 |
LOW
Network
|
mediawiki fedoraproject debian
|
mediawiki fedora debian_linux
|
In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had t…
|
NVD-CWE-noinfo
|
CVE-2020-15005
|
2024-11-21 14:04 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210618
|
4.8 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
PHP-Fusion 9.03.60 allows XSS via the administration/site_links.php Add Site Link field.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15041
|
2024-11-21 14:04 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210619
|
5.4 |
MEDIUM
Network
|
seedprod
|
coming_soon_page\ _under_construction_\&_maintenance_mode
|
The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15038
|
2024-11-21 14:04 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210620
|
4.9 |
MEDIUM
Network
|
bludit
|
bludit
|
Bludit 3.12.0 allows admins to use a /plugin-backup-download?file=../ directory traversal approach for arbitrary file download via backup/plugin.php.
|
CWE-22
Path Traversal
|
CVE-2020-15026
|
2024-11-21 14:04 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|