|
210761
|
7.5 |
HIGH
Network
|
zohocorp
|
manageengine_analytics_plus
|
Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via…
|
CWE-611
XXE
|
CVE-2020-21641
|
2024-11-21 14:12 |
2022-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210762
|
7.5 |
HIGH
Network
|
wkhtmltopdf debian
|
wkhtmltopdf debian_linux
|
Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configu…
|
CWE-22
Path Traversal
|
CVE-2020-21365
|
2024-11-21 14:12 |
2022-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210763
|
7.5 |
HIGH
Network
|
v88_smart_tv_box_project rk_max_smart_tv_box_project
|
v88_smart_tv_box_firmware rk_max_smart_tv_box_firmware
|
An issue was discovered in RK Smart TV Box MAX and V88 SmartTV box that allows attackers to cause a denial of service via the switchNextDisplayInterface service.
|
NVD-CWE-noinfo
|
CVE-2020-21406
|
2024-11-21 14:12 |
2022-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210764
|
7.5 |
HIGH
Network
|
h96tvbox
|
h96_pro_plus_firmware
|
An issue was discovered in H96 Smart TV Box H96 Pro Plus allows attackers to corrupt files via calls to the saveDeepColorAttr service.unk
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-21405
|
2024-11-21 14:12 |
2022-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210765
|
4.8 |
MEDIUM
Network
|
prestashop
|
prestashop
|
File upload vulnerability in the Catalog feature in Prestashop 1.7.6.7 allows remote attackers to run arbitrary code via the add new file page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21967
|
2024-11-21 14:12 |
2022-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210766
|
6.1 |
MEDIUM
Network
|
ruckuswireless
|
zonedirector_firmware
|
Cross Site Scripting (XSS) vulnerability in Ruckus Wireless ZoneDirector 9.8.3.0.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21161
|
2024-11-21 14:12 |
2022-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210767
|
7.8 |
HIGH
Local
|
softonic
|
eagleget
|
A local privilege escalation vulnerability was identified within the "luminati_net_updater_win_eagleget_com" service in EagleGet Downloader version 2.1.5.20 Stable. This issue allows authenticated no…
|
CWE-269
Improper Privilege Management
|
CVE-2020-21046
|
2024-11-21 14:12 |
2022-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210768
|
8.8 |
HIGH
Network
|
pbootcms
|
pbootcms
|
Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index.
|
CWE-352
Origin Validation Error
|
CVE-2020-20971
|
2024-11-21 14:12 |
2022-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210769
|
8.1 |
HIGH
Network
|
tinyrise
|
tinyshop
|
A File Deletion vulnerability exists in TinyShop 3.1.1 in the back_list parameter in controllers\admin.php, which could let a malicious user delete any file such as install.lock to reinstall cms.
|
NVD-CWE-noinfo
|
CVE-2020-21554
|
2024-11-21 14:12 |
2022-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210770
|
9.8 |
CRITICAL
Network
|
chshcms
|
cscms
|
An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-21238
|
2024-11-21 14:12 |
2021-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|