|
196001
|
6.5 |
MEDIUM
Network
|
soplanning
|
soplanning
|
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-9266
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196002
|
8.2 |
HIGH
Network
|
ciprianmp
|
phpmychat-plus
|
phpMyChat-Plus 1.98 is vulnerable to multiple SQL injections against the deluser.php Delete User functionality, as demonstrated by pmc_username.
|
CWE-89
SQL Injection
|
CVE-2020-9265
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196003
|
5.5 |
MEDIUM
Local
|
eset
|
nod32_antivirus internet_security smart_security mobile_security smart_tv_security cyber_security
|
ESET Archive Support Module before 1296 allows virus-detection bypass via a crafted Compression Information Field in a ZIP archive. This affects versions before 1294 of Smart Security Premium, Intern…
|
CWE-436
Interpretation Conflict
|
CVE-2020-9264
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196004
|
4.3 |
MEDIUM
Network
|
google
|
site_kit
|
The Site Kit by Google plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 1.8.0 This is due to the lack of capability checks on the admin_enqueue…
|
CWE-252
Unchecked Return Value
|
CVE-2020-8934
|
2024-11-21 14:39 |
2023-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196005
|
3.7 |
LOW
Network
|
shipstation
|
shipstation
|
The ShipStation.com plugin 1.1 and earlier for CS-Cart allows remote attackers to insert arbitrary information into the database (via action=shipnotify) because access to this endpoint is completely …
|
CWE-862
Missing Authorization
|
CVE-2020-9009
|
2024-11-21 14:39 |
2023-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196006
|
7.5 |
HIGH
Network
|
shipstation
|
shipstation
|
The ShipStation.com plugin 1.0 for CS-Cart allows remote attackers to obtain sensitive information (via action=export) because a typo results in a successful comparison of a blank password and NULL.
|
NVD-CWE-noinfo
|
CVE-2020-8889
|
2024-11-21 14:39 |
2023-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196007
|
8.8 |
HIGH
Network
|
zigor
|
zgr_tps200_ng_firmware
|
The integrated server of the ZGR TPS200 NG on its 2.00 firmware version and 1.01 hardware version, allows a remote attacker to perform actions with the permissions of a victim user. For this to happe…
|
CWE-352
Origin Validation Error
|
CVE-2020-8976
|
2024-11-21 14:39 |
2022-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196008
|
7.5 |
HIGH
Network
|
zigor
|
zgr_tps200_ng_firmware
|
ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, allows a remote attacker with access to the web application and knowledge of the routes (URIs) used by the application, to access…
|
CWE-200
Information Exposure
|
CVE-2020-8975
|
2024-11-21 14:39 |
2022-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196009
|
9.1 |
CRITICAL
Network
|
zigor
|
zgr_tps200_ng_firmware
|
In ZGR TPS200 NG 2.00 firmware version and 1.01 hardware version, the firmware upload process does not perform any type of restriction. This allows an attacker to modify it and re-upload it via web w…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-8974
|
2024-11-21 14:39 |
2022-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196010
|
8.1 |
HIGH
Adjacent
|
zigor
|
zgr_tps200_ng_firmware
|
ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, does not properly accept specially constructed requests. This allows an attacker with access to the network where the affected as…
|
NVD-CWE-noinfo
|
CVE-2020-8973
|
2024-11-21 14:39 |
2022-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|