|
210051
|
8.8 |
HIGH
Network
|
ucopia
|
ucopia_wireless_appliance
|
UCOPIA Wi-Fi appliances 6.0.5 allow authenticated remote attackers to escape the restricted administration shell CLI, and access a shell with admin user rights, via an unprotected less command.
|
CWE-78
OS Command
|
CVE-2020-25036
|
2024-11-21 14:16 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210052
|
6.7 |
MEDIUM
Local
|
ucopia
|
express_wireless_appliance
|
UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with root privileges using chroothole_client's PHP call, a related issue to CVE-2017-11322.
|
NVD-CWE-noinfo
|
CVE-2020-25035
|
2024-11-21 14:16 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210053
|
8.2 |
HIGH
Local
|
ucopia
|
ucopia_wireless_appliance
|
UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with admin user privileges via an escape from a restricted command.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-25037
|
2024-11-21 14:16 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210054
|
6.1 |
MEDIUM
Network
|
cutesoft
|
cute_editor
|
Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied input. A remote attacker could exploit this vulnerability using a spec…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24903
|
2024-11-21 14:16 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210055
|
6.1 |
MEDIUM
Network
|
quixplorer_project
|
quixplorer
|
Quixplorer <=2.4.1 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied input. A remote attacker could exploit this vulnerability using a specially cra…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24902
|
2024-11-21 14:16 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210056
|
6.1 |
MEDIUM
Network
|
krpano
|
krpano
|
The default installation of Krpano Panorama Viewer version <=1.20.8 is vulnerable to Reflected XSS due to insecure remote js load in file viewer/krpano.html, parameter plugin[test].url.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24901
|
2024-11-21 14:16 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210057
|
6.1 |
MEDIUM
Network
|
krpano
|
krpano
|
The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load in file /viewer/krpano.html, parameter xml.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24900
|
2024-11-21 14:16 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210058
|
9.8 |
CRITICAL
Network
|
kyland
|
kps2204_6_port_managed_din-rail_programmable_serial_device_firmware
|
A sensitive information disclosure vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 allows remote attackers to get username and pa…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-25011
|
2024-11-21 14:16 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210059
|
9.8 |
CRITICAL
Network
|
kyland
|
kps2204_6_port_managed_din-rail_programmable_serial_device_firmware
|
An arbitrary code execution vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 allows remote attackers to upload a malicious script …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-25010
|
2024-11-21 14:16 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210060
|
9.8 |
CRITICAL
Network
|
zyxel
|
zld_firmware access_points_firmware
|
A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitra…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-25014
|
2024-11-21 14:16 |
2020-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|