|
210651
|
9.8 |
CRITICAL
Network
|
smartstore
|
smartstore
|
Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plu…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-15243
|
2024-11-21 14:05 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210652
|
6.1 |
MEDIUM
Network
|
typo3
|
fluid_engine typo3
|
TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vulnerable to cross-site scripting when making use of the ternary conditional oper…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15241
|
2024-11-21 14:05 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210653
|
6.1 |
MEDIUM
Network
|
vercel
|
next.js
|
Next.js versions >=9.5.0 and <9.5.4 are vulnerable to an Open Redirect. Specially encoded paths could be used with the trailing slash redirect to allow an open redirect to occur to an external site. …
|
-
|
CVE-2020-15242
|
2024-11-21 14:05 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210654
|
5.9 |
MEDIUM
Network
|
mozilla
|
thunderbird
|
If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunde…
|
NVD-CWE-noinfo
|
CVE-2020-15646
|
2024-11-21 14:05 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210655
|
6.5 |
MEDIUM
Network
|
smarter
|
smarter_coffee_maker_1st_generation
|
Smarter Coffee Maker before 2nd generation allows firmware replacement without authentication or authorization. User interaction is required to press a button. NOTE: This vulnerability only affects p…
|
NVD-CWE-noinfo
|
CVE-2020-15501
|
2024-11-21 14:05 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210656
|
5.3 |
MEDIUM
Network
|
glpi-project
|
glpi
|
In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in version 9.5.0 and patched in 9.5.2. As a workaround, disable public access to …
|
-
|
CVE-2020-15217
|
2024-11-21 14:05 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210657
|
8.6 |
HIGH
Network
|
glpi-project
|
glpi
|
In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does not escape or sanitize allowing for SQL Injection to occur. Leveraging this vulne…
|
-
|
CVE-2020-15176
|
2024-11-21 14:05 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210658
|
4.3 |
MEDIUM
Network
|
glpi-project
|
glpi
|
In GLPI before version 9.5.2, there is a SQL Injection in the API's search function. Not only is it possible to break the SQL syntax, but it is also possible to utilise a UNION SELECT query to reflec…
|
-
|
CVE-2020-15226
|
2024-11-21 14:05 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210659
|
6.1 |
MEDIUM
Network
|
glpi-project
|
glpi
|
In GLPI before version 9.5.2, the `install/install.php` endpoint insecurely stores user input into the database as `url_base` and `url_base_api`. These settings are referenced throughout the applicat…
|
-
|
CVE-2020-15177
|
2024-11-21 14:05 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210660
|
9.1 |
CRITICAL
Network
|
glpi-project
|
glpi
|
In GLPI before version 9.5.2, the `?pluginimage.send.php?` endpoint allows a user to specify an image from a plugin. The parameters can be maliciously crafted to instead delete the .htaccess file for…
|
-
|
CVE-2020-15175
|
2024-11-21 14:05 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|