|
199611
|
5.9 |
MEDIUM
Network
|
voatz
|
voatz
|
The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover log…
|
CWE-330 CWE-521
Use of Insufficiently Random Values Weak Password Requirements
|
CVE-2020-8988
|
2024-11-21 14:39 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199612
|
6.1 |
MEDIUM
Network
|
mantisbt
|
source_integration
|
A cross-site scripting (XSS) vulnerability was discovered in the Source Integration plugin before 1.6.2 and 2.x before 2.3.1 for MantisBT. The repo_delete.php Delete Repository page allows execution …
|
CWE-79
Cross-site Scripting
|
CVE-2020-8981
|
2024-11-21 14:39 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199613
|
6.5 |
MEDIUM
Network
|
salesagility
|
suitecrm
|
SuiteCRM through 7.11.10 allows SQL Injection via the SOAP API, the EmailUIAjax interface, or the MailMerge module.
|
CWE-89
SQL Injection
|
CVE-2020-8804
|
2024-11-21 14:39 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199614
|
9.8 |
CRITICAL
Network
|
salesagility
|
suitecrm
|
SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list.
|
CWE-22
Path Traversal
|
CVE-2020-8803
|
2024-11-21 14:39 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199615
|
9.8 |
CRITICAL
Network
|
salesagility
|
suitecrm
|
SuiteCRM through 7.11.11 has Incorrect Access Control via action_saveHTMLField Bean Manipulation.
|
CWE-89
SQL Injection
|
CVE-2020-8802
|
2024-11-21 14:39 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199616
|
7.2 |
HIGH
Network
|
salesagility
|
suitecrm
|
SuiteCRM through 7.11.11 allows PHAR Deserialization.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-8801
|
2024-11-21 14:39 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199617
|
8.8 |
HIGH
Network
|
salesagility
|
suitecrm
|
SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection.
|
CWE-74
Injection
|
CVE-2020-8800
|
2024-11-21 14:39 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199618
|
9.8 |
CRITICAL
Network
|
askey
|
ap4000w_firmware
|
An issue was discovered on Askey AP4000W TDC_V1.01.003 devices. An attacker can perform Remote Code Execution (RCE) by sending a specially crafted network packer to the bd_svr service listening on TC…
|
CWE-20
Improper Input Validation
|
CVE-2020-8614
|
2024-11-21 14:39 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199619
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-842_firmware
|
A stack-based buffer overflow was found on the D-Link DIR-842 REVC with firmware v3.13B09 HOTFIX due to the use of strcpy for LOGINPASSWORD when handling a POST request to the /MTFWU endpoint.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-8962
|
2024-11-21 14:39 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199620
|
9.8 |
CRITICAL
Network
|
openvpn
|
openvpn_access_server
|
OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).
|
CWE-287
Improper Authentication
|
CVE-2020-8953
|
2024-11-21 14:39 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|