|
210591
|
5.4 |
MEDIUM
Network
|
midasolutions
|
eframework
|
Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15918
|
2024-11-21 14:06 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210592
|
9.8 |
CRITICAL
Network
|
claws-mail fedoraproject opensuse
|
claws-mail fedora leap backports_sle
|
common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.
|
NVD-CWE-noinfo
|
CVE-2020-15917
|
2024-11-21 14:06 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210593
|
9.8 |
CRITICAL
Network
|
tenda
|
ac15_firmware
|
goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parameter.
|
CWE-78
OS Command
|
CVE-2020-15916
|
2024-11-21 14:06 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210594
|
6.5 |
MEDIUM
Adjacent
|
tesla
|
model_3_firmware
|
Tesla Model 3 vehicles allow attackers to open a door by leveraging access to a legitimate key card, and then using NFC Relay. NOTE: the vendor has developed Pin2Drive to mitigate this issue
|
NVD-CWE-noinfo
|
CVE-2020-15912
|
2024-11-21 14:06 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210595
|
8.8 |
HIGH
Network
|
softwareupdate_project
|
softwareupdate
|
A SQL injection vulnerability in softwareupdate_controller.php in the Software Update module before 1.6 for MunkiReport allows attackers to execute arbitrary SQL commands via the last URL parameter o…
|
CWE-89
SQL Injection
|
CVE-2020-15887
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210596
|
8.8 |
HIGH
Network
|
reportdata_project
|
reportdata
|
A SQL injection vulnerability in reportdata_controller.php in the reportdata module before 3.5 for MunkiReport allows attackers to execute arbitrary SQL commands via the req parameter of the /module/…
|
CWE-89
SQL Injection
|
CVE-2020-15886
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210597
|
5.4 |
MEDIUM
Network
|
munkireport_project
|
comment
|
A Cross-Site Scripting (XSS) vulnerability in the comment module before 4.0 for MunkiReport allows remote attackers to inject arbitrary web script or HTML by posting a new comment.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15885
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210598
|
8.8 |
HIGH
Network
|
munkireport_project
|
munkireport
|
A SQL injection vulnerability in TableQuery.php in MunkiReport before 5.6.3 allows attackers to execute arbitrary SQL commands via the order[0][dir] field on POST requests to /datatables/data.
|
CWE-89
SQL Injection
|
CVE-2020-15884
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210599
|
6.1 |
MEDIUM
Network
|
managedinstalls_project
|
managedinstalls
|
A Cross-Site Scripting (XSS) vulnerability in the managedinstalls module before 2.6 for MunkiReport allows remote attackers to inject arbitrary web script or HTML via the last two URL parameters (thr…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15883
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210600
|
8.1 |
HIGH
Network
|
munkireport_project
|
munkireport
|
A CSRF issue in manager/delete_machine/{id} in MunkiReport before 5.6.3 allows attackers to delete arbitrary machines from the MunkiReport database.
|
CWE-352
Origin Validation Error
|
CVE-2020-15882
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|