|
210651
|
6.1 |
MEDIUM
Network
|
flexmonster
|
pivot_table_\&_charts
|
Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20140
|
2024-11-21 14:11 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210652
|
6.1 |
MEDIUM
Network
|
flexmonster
|
pivot_table_\&_charts
|
Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20139
|
2024-11-21 14:11 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210653
|
6.1 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
Cross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20138
|
2024-11-21 14:11 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210654
|
9.8 |
CRITICAL
Network
|
newpk_project
|
newpk
|
SQL Injection vulnerability in NewPK 1.1 via the title parameter to admin\newpost.php.
|
CWE-89
SQL Injection
|
CVE-2020-20189
|
2024-11-21 14:11 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210655
|
9.8 |
CRITICAL
Network
|
liftoffsoftware
|
gateone
|
GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.
|
CWE-78
OS Command
|
CVE-2020-20184
|
2024-11-21 14:11 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210656
|
7.5 |
HIGH
Network
|
zyxel
|
p1302-t10_v3_firmware
|
Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier allows attackers to gain privileges and access certain admin pages.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-20183
|
2024-11-21 14:11 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210657
|
9.8 |
CRITICAL
Network
|
quantconnect
|
lean
|
QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-20136
|
2024-11-21 14:11 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210658
|
5.9 |
MEDIUM
Network
|
openssl debian fedoraproject oracle netapp tenable siemens nodejs
|
openssl debian_linux fedora api_gateway peoplesoft_enterprise_peopletools business_intelligence jd_edwards_world_security enterprise_manager_base_platform http_server enter…
|
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares d…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-1971
|
2024-11-21 14:11 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210659
|
4.3 |
MEDIUM
Network
|
otrs
|
otrs
|
When OTRS uses multiple backends for user authentication (with LDAP), agents are able to login even if the account is set to invalid. This issue affects OTRS; 8.0.9 and prior versions.
|
CWE-287
Improper Authentication
|
CVE-2020-1778
|
2024-11-21 14:11 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210660
|
7.5 |
HIGH
Network
|
huawei
|
nip6300_firmware nip6600_firmware secospace_usg6300_firmware secospace_usg6500_firmware secospace_usg6600_firmware usg9500_firmware
|
There is a denial of service vulnerability in some Huawei products. There is no protection against the attack scenario of specific protocol. A remote, unauthorized attackers can construct attack scen…
|
NVD-CWE-noinfo
|
CVE-2020-1847
|
2024-11-21 14:11 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|