|
196661
|
6.1 |
MEDIUM
Network
|
openmrs
|
openmrs
|
In OpenMRS 2.9 and prior, the sessionLocation parameter for the login page is vulnerable to cross-site scripting.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5730
|
2024-11-21 14:34 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196662
|
6.1 |
MEDIUM
Network
|
openmrs
|
openmrs
|
In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which can result in XSS. Any page that is able to trigger a UI Framework Error is su…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5729
|
2024-11-21 14:34 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196663
|
6.1 |
MEDIUM
Network
|
openmrs
|
openmrs
|
OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (such as login.htm). There is insufficient validation for this parameter, which all…
|
CWE-79 CWE-20
Cross-site Scripting Improper Input Validation
|
CVE-2020-5728
|
2024-11-21 14:34 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196664
|
5.5 |
MEDIUM
Local
|
mikrotik
|
winbox
|
MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file when the Keep Password field is set and no Master Password is set. Keep Password is set …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-5721
|
2024-11-21 14:34 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196665
|
8.8 |
HIGH
Network
|
grandstream
|
gxp1610_firmware gxp1615_firmware gxp1620_firmware gxp1625_firmware gxp1628_firmware gxp1630_firmware
|
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up script to the phone's VPN settings via the "Additio…
|
CWE-94
Code Injection
|
CVE-2020-5739
|
2024-11-21 14:34 |
2020-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196666
|
8.8 |
HIGH
Network
|
grandstream
|
gxp1610_firmware gxp1615_firmware gxp1620_firmware gxp1625_firmware gxp1628_firmware gxp1630_firmware
|
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a specially crafted tar file to the HTTP /cgi-bin/upload_vpnta…
|
CWE-59
Link Following
|
CVE-2020-5738
|
2024-11-21 14:34 |
2020-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196667
|
6.5 |
MEDIUM
Network
|
vmware
|
tanzu_application_service_for_vms
|
VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes a version of PCF Autoscaling that writes database…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-5406
|
2024-11-21 14:34 |
2020-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196668
|
6.5 |
MEDIUM
Network
|
amcrest
|
1080-lite_8ch_firmware amdv10814-h5_firmware ipm-721_firmware ip2m-841_firmware ip2m-841-v3_firmware ip2m-853ew_firmware ip2m-858w_firmware ip2m-866w_firmware ip2m-866ew_firmw…
|
Amcrest cameras and NVR are vulnerable to a null pointer dereference over port 37777. An authenticated remote attacker can abuse this issue to crash the device.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-5736
|
2024-11-21 14:34 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196669
|
8.1 |
HIGH
Network
|
plathome
|
easyblocks_ipv6_firmware easyblocks_ipv6_enterprise_firmware
|
Session fixation vulnerability in EasyBlocks IPv6 Ver. 2.0.1 and earlier, and Enterprise Ver. 2.0.1 and earlier allows remote attackers to impersonate a registered user and log in the management cons…
|
CWE-384
Session Fixation
|
CVE-2020-5550
|
2024-11-21 14:34 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196670
|
8.8 |
HIGH
Network
|
plathome
|
easyblocks_ipv6_firmware easyblocks_ipv6_enterprise_firmware
|
Cross-site request forgery (CSRF) vulnerability in EasyBlocks IPv6 Ver. 2.0.1 and earlier and Enterprise Ver. 2.0.1 and earlier allows remote attackers to hijack the authentication of administrators …
|
CWE-352
Origin Validation Error
|
CVE-2020-5549
|
2024-11-21 14:34 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|