|
210601
|
6.1 |
MEDIUM
Network
|
munki_facts_project
|
munki_facts
|
A Cross-Site Scripting (XSS) vulnerability in the munki_facts (aka Munki Conditions) module before 1.5 for MunkiReport allows remote attackers to inject arbitrary web script or HTML via the key name.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15881
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210602
|
8.8 |
HIGH
Network
|
embedthis
|
goahead
|
The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthenticated remote attacker to bypass authentication via c…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2020-15688
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210603
|
7.5 |
HIGH
Network
|
cauldrondevelopment
|
c\!
|
tar/TarFileReader.cpp in Cauldron cbang (aka C-Bang or C!) before 1.6.0 allows Directory Traversal during extraction from a TAR archive.
|
CWE-22
Path Traversal
|
CVE-2020-15908
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210604
|
7.8 |
HIGH
Local
|
pypi
|
bsdiff4
|
A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond allocated bounds) via a crafted patch file.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-15904
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210605
|
6.1 |
MEDIUM
Network
|
nagios
|
nagios_xi
|
Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15902
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210606
|
8.8 |
HIGH
Network
|
nagios
|
nagios_xi
|
In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys.
|
NVD-CWE-noinfo
|
CVE-2020-15901
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210607
|
6.1 |
MEDIUM
Network
|
dlink
|
dir-816l_firmware
|
An XSS issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. In the file webinc/js/info.php, no output filtration is applied to the RESULT parameter, before it's printed on the we…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15895
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210608
|
7.5 |
HIGH
Network
|
dlink
|
dir-816l_firmware
|
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. There exists an exposed administration function in getcfg.php, which can be used to call various services. It can be utili…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-15894
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210609
|
7.5 |
HIGH
Network
|
dlink
|
dap-1522_firmware
|
An authentication-bypass issue was discovered on D-Link DAP-1522 devices 1.4x before 1.10b04Beta02. There exist a few pages that are directly accessible by any unauthorized user, e.g., logout.php and…
|
CWE-287
Improper Authentication
|
CVE-2020-15896
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210610
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-816l_firmware
|
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting …
|
CWE-78
OS Command
|
CVE-2020-15893
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|