|
198321
|
6.1 |
MEDIUM
Network
|
masscode
|
masscode
|
massCode 1.0.0-alpha.6 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in webPreferences is true).
|
CWE-79
Cross-site Scripting
|
CVE-2020-8548
|
2024-11-21 14:39 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198322
|
9.8 |
CRITICAL
Network
|
phplist
|
phplist
|
phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical character…
|
NVD-CWE-noinfo
|
CVE-2020-8547
|
2024-11-21 14:39 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198323
|
7.5 |
HIGH
Network
|
circl
|
ail_framework
|
Global.py in AIL framework 2.8 allows path traversal.
|
CWE-22
Path Traversal
|
CVE-2020-8545
|
2024-11-21 14:39 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198324
|
- |
|
-
|
-
|
The server in Circontrol Raption through 5.11.2 has a pre-authentication stack-based buffer overflow that can be exploited to gain run-time control of the device as root. The ocpp1.5 and pwrstudio bi…
|
-
|
CVE-2020-8006
|
2024-11-21 14:38 |
2024-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198325
|
7.2 |
HIGH
Network
|
expressionengine
|
expressionengine
|
Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user needs member creation/admin control panel access to execute the attack.
|
CWE-89
SQL Injection
|
CVE-2020-8242
|
2024-11-21 14:38 |
2022-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198326
|
7.8 |
HIGH
Local
|
bitdefender
|
total_security internet_security antivirus_plus
|
A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper with product settings via a specially crafted DLL file. This issue affects: Bi…
|
NVD-CWE-Other
|
CVE-2020-8107
|
2024-11-21 14:38 |
2022-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198327
|
7.8 |
HIGH
Local
|
goabode
|
iota_all-in-one_security_kit_firmware
|
OS Command Injection vulnerability in the wirelessConnect handler of Abode iota All-In-One Security Kit allows an attacker to inject commands and gain root access. This issue affects: Abode iota All-…
|
CWE-78
OS Command
|
CVE-2020-8105
|
2024-11-21 14:38 |
2021-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198328
|
6.1 |
MEDIUM
Network
|
rocket.chat
|
rocket.chat
|
A link preview rendering issue in Rocket.Chat versions before 3.9 could lead to potential XSS attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8291
|
2024-11-21 14:38 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198329
|
6.5 |
MEDIUM
Network
|
citrix
|
netscaler_gateway gateway application_delivery_controller_firmware
|
Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack t…
|
NVD-CWE-Other
|
CVE-2020-8300
|
2024-11-21 14:38 |
2021-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198330
|
6.5 |
MEDIUM
Adjacent
|
citrix
|
netscaler_gateway gateway application_delivery_controller_firmware sd-wan_wanop
|
Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-8299
|
2024-11-21 14:38 |
2021-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|