|
210701
|
6.1 |
MEDIUM
Network
|
nedi
|
nedi
|
NeDi 1.9C is vulnerable to reflected cross-site scripting. The Other-Converter.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15016
|
2024-11-21 14:04 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210702
|
5.9 |
MEDIUM
Network
|
trojita_project
|
trojita
|
MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to spoof SMTP servers.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-15047
|
2024-11-21 14:04 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210703
|
8.8 |
HIGH
Network
|
supermicro
|
x10drh-it_bios x10drh-it_firmware
|
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed ver…
|
CWE-352
Origin Validation Error
|
CVE-2020-15046
|
2024-11-21 14:04 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210704
|
3.1 |
LOW
Network
|
mediawiki fedoraproject debian
|
mediawiki fedora debian_linux
|
In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had t…
|
NVD-CWE-noinfo
|
CVE-2020-15005
|
2024-11-21 14:04 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210705
|
4.8 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
PHP-Fusion 9.03.60 allows XSS via the administration/site_links.php Add Site Link field.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15041
|
2024-11-21 14:04 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210706
|
5.4 |
MEDIUM
Network
|
seedprod
|
coming_soon_page\ _under_construction_\&_maintenance_mode
|
The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15038
|
2024-11-21 14:04 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210707
|
4.9 |
MEDIUM
Network
|
bludit
|
bludit
|
Bludit 3.12.0 allows admins to use a /plugin-backup-download?file=../ directory traversal approach for arbitrary file download via backup/plugin.php.
|
CWE-22
Path Traversal
|
CVE-2020-15026
|
2024-11-21 14:04 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210708
|
4.9 |
MEDIUM
Network
|
ntp opensuse netapp oracle
|
ntp leap cloud_backup steelstore_cloud_integrated_storage 8300_firmware 8700_firmware a400_firmware h410c_firmware h300s_firmware h500s_firmware h700s_firmware h300e_…
|
ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations wher…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-15025
|
2024-11-21 14:04 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210709
|
6.1 |
MEDIUM
Network
|
gleamtech
|
fileultimate
|
The FileExplorer component in GleamTech FileUltimate 6.1.5.0 allows XSS via an SVG document.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15015
|
2024-11-21 14:04 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210710
|
6.5 |
MEDIUM
Network
|
playsms
|
playsms
|
playSMS through 1.4.3 is vulnerable to session fixation.
|
CWE-384
Session Fixation
|
CVE-2020-15018
|
2024-11-21 14:04 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|