|
199591
|
7.2 |
HIGH
Network
|
liferay
|
liferay_portal
|
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject Groovy script to execute any OS command on the Liferay Portal Sever. NOTE: T…
|
CWE-78
OS Command
|
CVE-2020-28884
|
2024-11-21 14:23 |
2022-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199592
|
5.4 |
MEDIUM
Network
|
checkmk
|
checkmk
|
A stored cross site scripting (XSS) vulnerability in Checkmk 1.6.0x prior to 1.6.0p19 allows an authenticated remote attacker to inject arbitrary JavaScript via a javascript: URL in a view title.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28919
|
2024-11-21 14:23 |
2022-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199593
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_applications_manager
|
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
|
CWE-89
SQL Injection
|
CVE-2020-28679
|
2024-11-21 14:23 |
2022-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199594
|
7.5 |
HIGH
Network
|
sphinxsearch debian
|
sphinx debian_linux
|
SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operation…
|
CWE-22
Path Traversal
|
CVE-2020-29050
|
2024-11-21 14:23 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199595
|
6.5 |
MEDIUM
Network
|
iball
|
wrd12en_firmware
|
iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or modifying the range for IP addresses.
|
CWE-352
Origin Validation Error
|
CVE-2020-29292
|
2024-11-21 14:23 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199596
|
9.1 |
CRITICAL
Network
|
zblogcn
|
z-blogphp
|
Z-BlogPHP v1.6.1.2100 was discovered to contain an arbitrary file deletion vulnerability via \app_del.php.
|
NVD-CWE-Other
|
CVE-2020-29177
|
2024-11-21 14:23 |
2021-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199597
|
7.8 |
HIGH
Local
|
zblogcn
|
z-blogphp
|
An arbitrary file upload vulnerability in Z-BlogPHP v1.6.1.2100 allows attackers to execute arbitrary code via a crafted JPG file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-29176
|
2024-11-21 14:23 |
2021-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199598
|
7.5 |
HIGH
Network
|
pybbs_project
|
pybbs
|
A SQL injection vulnerability in TopicMapper.xml of PybbsCMS v5.2.1 allows attackers to access sensitive database information.
|
CWE-89
SQL Injection
|
CVE-2020-28702
|
2024-11-21 14:23 |
2021-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199599
|
7.8 |
HIGH
Local
|
aplixio
|
pdf_shapingup
|
Aplioxio PDF ShapingUp 5.0.0.139 contains a buffer overflow which allows attackers to cause a denial of service (DoS) via a crafted PDF file.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-28969
|
2024-11-21 14:23 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199600
|
5.4 |
MEDIUM
Network
|
draytek
|
vigorap_1000c_firmware vigorap_700_firmware vigorap_710_firmware vigorap_800_firmware vigorap_802_firmware vigorap_810_firmware vigorap_900_firmware vigorap_902_firmware vigor…
|
Draytek VigorAP 1000C contains a stored cross-site scripting (XSS) vulnerability in the RADIUS Setting - RADIUS Server Configuration module. This vulnerability allows attackers to execute arbitrary w…
|
CWE-79
Cross-site Scripting
|
CVE-2020-28968
|
2024-11-21 14:23 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|