|
199671
|
7.5 |
HIGH
Network
|
libslirp_project qemu
|
libslirp qemu
|
tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.
|
CWE-22
Path Traversal
|
CVE-2020-7211
|
2024-11-21 14:36 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199672
|
5.5 |
MEDIUM
Local
|
taskautomation
|
carbonftp
|
CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FTP server passwords is hard-coded in the binary.
|
CWE-798 CWE-327
Use of Hard-coded Credentials Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-6857
|
2024-11-21 14:36 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199673
|
8.8 |
HIGH
Network
|
qdpm
|
qdpm
|
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo functionality, by leveraging a path traversal vulner…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2020-7246
|
2024-11-21 14:36 |
2020-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199674
|
6.1 |
MEDIUM
Network
|
ibm
|
chatbot_with_ibm_watson
|
The conversation-watson plugin before 0.8.21 for WordPress has a DOM-based XSS vulnerability that is executed when a chat message containing JavaScript is sent.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7239
|
2024-11-21 14:36 |
2020-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199675
|
4.8 |
MEDIUM
Network
|
smc
|
d3g0804_firmware
|
SMC D3G0804W 3.5.2.5-LAT_GA devices allow XSS via the SSID field on the WiFi Network Configuration page (after a successful login to the admin account).
|
CWE-79
Cross-site Scripting
|
CVE-2020-7249
|
2024-11-21 14:36 |
2020-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199676
|
7.2 |
HIGH
Network
|
comtechtel
|
stampede_fx-1010_firmware
|
Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Poll Routes page and entering shell metacharacters in the Router…
|
CWE-78
OS Command
|
CVE-2020-7244
|
2024-11-21 14:36 |
2020-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199677
|
7.2 |
HIGH
Network
|
comtechtel
|
stampede_fx-1010_firmware
|
Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Fetch URL page and entering shell metacharacters in the URL fiel…
|
CWE-78
OS Command
|
CVE-2020-7243
|
2024-11-21 14:36 |
2020-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199678
|
7.2 |
HIGH
Network
|
comtechtel
|
stampede_fx-1010_firmware
|
Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Diagnostics Trace Route page and entering shell metacharacters i…
|
CWE-78
OS Command
|
CVE-2020-7242
|
2024-11-21 14:36 |
2020-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199679
|
7.5 |
HIGH
Network
|
wpseeds
|
wp_database_backup
|
The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/uploads/db-backup/. This might allow attackers to read ZIP archives by guessing…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-7241
|
2024-11-21 14:36 |
2020-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199680
|
5.5 |
MEDIUM
Local
|
gallagher
|
command_centre
|
An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4). External system configuration data (used for third party inte…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-7215
|
2024-11-21 14:36 |
2020-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|