|
196391
|
8.8 |
HIGH
Network
|
webfactoryltd
|
wp_database_reset
|
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability (with a simple wp-admin/admin.php?db-reset-tables[]=users …
|
CWE-269
Improper Privilege Management
|
CVE-2020-7047
|
2024-11-21 14:36 |
2020-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196392
|
5.4 |
MEDIUM
Network
|
learndash
|
learndash
|
The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7108
|
2024-11-21 14:36 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196393
|
6.1 |
MEDIUM
Network
|
etoilewebdesign
|
ultimate_faq
|
The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7107
|
2024-11-21 14:36 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196394
|
6.1 |
MEDIUM
Network
|
cacti debian opensuse suse fedoraproject
|
cacti debian_linux leap backports_sle package_hub fedora extra_packages_for_enterprise_linux
|
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the descrip…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7106
|
2024-11-21 14:36 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196395
|
7.5 |
HIGH
Network
|
redislabs debian fedoraproject
|
hiredis debian_linux fedora
|
async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-7105
|
2024-11-21 14:36 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196396
|
6.5 |
MEDIUM
Adjacent
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by validating opcodes.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-7045
|
2024-11-21 14:36 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196397
|
7.5 |
HIGH
Network
|
wireshark fedoraproject opensuse oracle
|
wireshark fedora leap solaris zfs_storage_appliance_kit
|
In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors.
|
CWE-125 CWE-193
Out-of-bounds Read Off-by-one Error
|
CVE-2020-7044
|
2024-11-21 14:36 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196398
|
8.8 |
HIGH
Network
|
cacti
|
cacti
|
data_input.php in Cacti 1.2.8 allows remote code execution via a crafted Input String to Data Collection -> Data Input Methods -> Unix -> Ping Host. NOTE: the vendor has stated "This is a false alarm.
|
CWE-20
Improper Input Validation
|
CVE-2020-7058
|
2024-11-21 14:36 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196399
|
5.3 |
MEDIUM
Network
|
hikvision
|
ds-7204hghi-f1_firmware
|
Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version sends a different response for failed ISAPI/Security/sessionLogin/capabilities login attempts depending on whether the user account exists…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-7057
|
2024-11-21 14:36 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196400
|
8.8 |
HIGH
Network
|
mz-automation
|
libiec61850
|
MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c in libIEC61850 through 1.4.0 has a heap-based buffer overflow when parsing the MMS_BIT_STRING data type.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7054
|
2024-11-21 14:36 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|