|
196311
|
9.8 |
CRITICAL
Network
|
intelliantech
|
aptus
|
The Intellian Aptus application 1.0.2 for Android has hardcoded values for DOWNLOAD_API_KEY and FILE_DOWNLOAD_API_KEY.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-7999
|
2024-11-21 14:38 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196312
|
6.1 |
MEDIUM
Network
|
dolibarr
|
dolibarr_erp\/crm
|
htdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows XSS via the Referer HTTP header.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7996
|
2024-11-21 14:38 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196313
|
9.8 |
CRITICAL
Network
|
dolibarr
|
dolibarr_erp\/crm
|
The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-7995
|
2024-11-21 14:38 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196314
|
6.1 |
MEDIUM
Network
|
dolibarr
|
dolibarr_erp\/crm
|
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 10.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) label[libelle] parameter to the /htdocs/admin/dict.php…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7994
|
2024-11-21 14:38 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196315
|
8.8 |
HIGH
Network
|
adive
|
framework
|
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
|
CWE-352
Origin Validation Error
|
CVE-2020-7991
|
2024-11-21 14:38 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196316
|
6.1 |
MEDIUM
Network
|
adive
|
framework
|
Adive Framework 2.0.8 has admin/user/add userName XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7990
|
2024-11-21 14:38 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196317
|
6.1 |
MEDIUM
Network
|
adive
|
framework
|
Adive Framework 2.0.8 has admin/user/add userUsername XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7989
|
2024-11-21 14:38 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196318
|
7.5 |
HIGH
Network
|
solarwinds
|
n-central
|
SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive inf…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-7984
|
2024-11-21 14:38 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196319
|
9.8 |
CRITICAL
Network
|
rubygeocoder
|
geocoder
|
sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data.
|
CWE-89
SQL Injection
|
CVE-2020-7981
|
2024-11-21 14:38 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196320
|
9.8 |
CRITICAL
Network
|
intelliantech
|
aptus_web
|
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. NOTE: a valid sid cookie for a login to the intelli…
|
CWE-78
OS Command
|
CVE-2020-7980
|
2024-11-21 14:38 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|