|
197491
|
7.5 |
HIGH
Network
|
microchip
|
syncserver_s100_firmware syncserver_s200_firmware syncserver_s250_firmware syncserver_s300_firmware syncserver_s350_firmware
|
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to unauthenticated creation, modification, or elimination of us…
|
NVD-CWE-noinfo
|
CVE-2020-9034
|
2024-11-21 14:39 |
2020-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197492
|
5.4 |
MEDIUM
Network
|
dolibarr
|
dolibarr_erp\/crm
|
Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header.
|
CWE-79
Cross-site Scripting
|
CVE-2020-9016
|
2024-11-21 14:39 |
2020-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197493
|
4.3 |
MEDIUM
Network
|
arvato
|
skillpipe
|
Arvato Skillpipe 3.0 allows attackers to bypass intended print restrictions by deleting <div id="watermark"> from the HTML source code.
|
CWE-20
Improper Input Validation
|
CVE-2020-9013
|
2024-11-21 14:39 |
2020-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197494
|
6.1 |
MEDIUM
Network
|
gluu
|
gluu_server
|
A cross-site scripting (XSS) vulnerability in the Import People functionality in Gluu Identity Configuration 4.0 allows remote attackers to inject arbitrary web script or HTML via the filename parame…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9012
|
2024-11-21 14:39 |
2020-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197495
|
5.4 |
MEDIUM
Network
|
codologic
|
codoforum
|
Codoforum 4.8.8 allows self-XSS via the title of a new topic.
|
CWE-79
Cross-site Scripting
|
CVE-2020-9007
|
2024-11-21 14:39 |
2020-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197496
|
8.8 |
HIGH
Adjacent
|
abbott
|
freestyle_libre_firmware
|
Older generation Abbott FreeStyle Libre sensors allow remote attackers within close proximity to enable write access to memory via a specific NFC unlock command. NOTE: The vulnerability is not presen…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-8997
|
2024-11-21 14:39 |
2020-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197497
|
4.3 |
MEDIUM
Network
|
aishu
|
anyshare_cloud
|
AnyShare Cloud 6.0.9 allows authenticated directory traversal to read files, as demonstrated by the interface/downloadwithpath/downloadfile/?filepath=/etc/passwd URI.
|
CWE-22
Path Traversal
|
CVE-2020-8996
|
2024-11-21 14:39 |
2020-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197498
|
5.4 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms
|
The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8594
|
2024-11-21 14:39 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197499
|
7.4 |
HIGH
Network
|
istio
|
istio
|
An issue was discovered in Istio 1.3 through 1.3.6. Under certain circumstances, it is possible to bypass a specifically configured Mixer policy. Istio-proxy accepts the x-istio-attributes header at …
|
CWE-20
Improper Input Validation
|
CVE-2020-8843
|
2024-11-21 14:39 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197500
|
9.0 |
CRITICAL
Network
|
progess progress
|
moveit_transfer
|
In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately sanitize malicious input, which could allow an authenticated attacker to execut…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8612
|
2024-11-21 14:39 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|