|
210671
|
7.5 |
HIGH
Network
|
connectwise
|
connectwise_automate
|
A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate serv…
|
CWE-89
SQL Injection
|
CVE-2020-15008
|
2024-11-21 14:04 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210672
|
4.4 |
MEDIUM
Local
|
npmjs opensuse fedoraproject
|
npm leap fedora
|
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:…
|
-
|
CVE-2020-15095
|
2024-11-21 14:04 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210673
|
5.4 |
MEDIUM
Network
|
nedi
|
nedi
|
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Monitoring-Map.php hde parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15035
|
2024-11-21 14:04 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210674
|
5.4 |
MEDIUM
Network
|
nedi
|
nedi
|
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Monitoring-Setup.php tet parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15034
|
2024-11-21 14:04 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210675
|
5.4 |
MEDIUM
Network
|
nedi
|
nedi
|
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the snmpget.php ip parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15033
|
2024-11-21 14:04 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210676
|
5.4 |
MEDIUM
Network
|
nedi
|
nedi
|
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Monitoring-Incidents.php id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15032
|
2024-11-21 14:04 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210677
|
5.4 |
MEDIUM
Network
|
nedi
|
nedi
|
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Assets-Management.php chg parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15031
|
2024-11-21 14:04 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210678
|
5.4 |
MEDIUM
Network
|
nedi
|
nedi
|
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Routes.php rtr parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15030
|
2024-11-21 14:04 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210679
|
5.4 |
MEDIUM
Network
|
nedi
|
nedi
|
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Assets-Management.php sn parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15029
|
2024-11-21 14:04 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210680
|
5.4 |
MEDIUM
Network
|
nedi
|
nedi
|
NeDi 1.9C is vulnerable to a cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Map.php xo parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15028
|
2024-11-21 14:04 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|