|
209781
|
9.8 |
CRITICAL
Network
|
gogogate
|
ismartgate_pro_firmware
|
ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-12838
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209782
|
7.5 |
HIGH
Network
|
gogogate
|
ismartgate_pro_firmware
|
ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading images to garage doors. The magic bytes of PNG must be used.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-12837
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209783
|
5.3 |
MEDIUM
Network
|
fortinet
|
fortios
|
An insufficient logging vulnerability in FortiGate before 6.4.1 may allow the traffic from an unauthenticated attacker to Fortinet owned IP addresses to go unnoticed.
|
NVD-CWE-Other
|
CVE-2020-12818
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209784
|
8.8 |
HIGH
Network
|
fortinet
|
fortitester fortianalyzer
|
An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticated attacker to inject script related HTML tags via Name parameter of Storage Co…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12817
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209785
|
6.1 |
MEDIUM
Network
|
fortinet
|
fortinac
|
An improper neutralization of input vulnerability in FortiNAC before 8.7.2 may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the UserID of Admin User…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12816
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209786
|
6.1 |
MEDIUM
Network
|
rad
|
secflow-1v_firmware
|
A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated attacker to upload a JavaScript file, with a stored XSS payload, that will rema…
|
CWE-79 CWE-434
Cross-site Scripting Unrestricted Upload of File with Dangerous Type
|
CVE-2020-13260
|
2024-11-21 14:00 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209787
|
9.0 |
CRITICAL
Network
|
solarwinds
|
orion_platform
|
Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation …
|
CWE-79
Cross-site Scripting
|
CVE-2020-13169
|
2024-11-21 14:00 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209788
|
8.8 |
HIGH
Network
|
rad
|
secflow-1v_firmware
|
A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attac…
|
CWE-352
Origin Validation Error
|
CVE-2020-13259
|
2024-11-21 14:00 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209789
|
4.7 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not revoking current user sessions when 2 factor authentication was activated allowing a malicious user…
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-13307
|
2024-11-21 14:00 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209790
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public …
|
CWE-287
Improper Authentication
|
CVE-2020-13303
|
2024-11-21 14:00 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|