|
198281
|
8.8 |
HIGH
Network
|
adive
|
framework
|
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
|
CWE-352
Origin Validation Error
|
CVE-2020-7991
|
2024-11-21 14:38 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198282
|
6.1 |
MEDIUM
Network
|
adive
|
framework
|
Adive Framework 2.0.8 has admin/user/add userName XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7990
|
2024-11-21 14:38 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198283
|
6.1 |
MEDIUM
Network
|
adive
|
framework
|
Adive Framework 2.0.8 has admin/user/add userUsername XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7989
|
2024-11-21 14:38 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198284
|
7.5 |
HIGH
Network
|
solarwinds
|
n-central
|
SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive inf…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-7984
|
2024-11-21 14:38 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198285
|
9.8 |
CRITICAL
Network
|
rubygeocoder
|
geocoder
|
sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data.
|
CWE-89
SQL Injection
|
CVE-2020-7981
|
2024-11-21 14:38 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198286
|
9.8 |
CRITICAL
Network
|
intelliantech
|
aptus_web
|
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. NOTE: a valid sid cookie for a login to the intelli…
|
CWE-78
OS Command
|
CVE-2020-7980
|
2024-11-21 14:38 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198287
|
5.3 |
MEDIUM
Network
|
mirumee
|
saleor
|
An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user ID and consequently…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-7964
|
2024-11-21 14:38 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198288
|
9.8 |
CRITICAL
Network
|
plone
|
plone
|
A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission.
|
NVD-CWE-noinfo
|
CVE-2020-7941
|
2024-11-21 14:38 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198289
|
7.5 |
HIGH
Network
|
plone
|
plone
|
Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.
|
CWE-521
Weak Password Requirements
|
CVE-2020-7940
|
2024-11-21 14:38 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198290
|
8.8 |
HIGH
Network
|
plone
|
plone
|
SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)
|
CWE-89
SQL Injection
|
CVE-2020-7939
|
2024-11-21 14:38 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|