|
209481
|
9.1 |
CRITICAL
Network
|
auth0
|
express-jwt
|
In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When algorithms is not specified in the configuration, wi…
|
CWE-863
Incorrect Authorization
|
CVE-2020-15084
|
2024-11-21 14:04 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209482
|
7.8 |
HIGH
Local
|
arswp
|
windows_cleanup_assistant
|
In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input value…
|
CWE-20
Improper Input Validation
|
CVE-2020-14957
|
2024-11-21 14:04 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209483
|
7.8 |
HIGH
Local
|
arswp
|
windows_cleanup_assistant
|
In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input value…
|
CWE-20
Improper Input Validation
|
CVE-2020-14956
|
2024-11-21 14:04 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209484
|
9.8 |
CRITICAL
Network
|
sophos
|
xg_firewall_firmware
|
Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-15069
|
2024-11-21 14:04 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209485
|
6.5 |
MEDIUM
Network
|
iball
|
wrb303n_firmware
|
iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP addresses.
|
CWE-352
Origin Validation Error
|
CVE-2020-15043
|
2024-11-21 14:04 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209486
|
5.5 |
MEDIUM
Local
|
jiangmin
|
jiangmin_antivirus
|
In Jiangmin Antivirus 16.0.13.129, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values f…
|
CWE-20
Improper Input Validation
|
CVE-2020-14955
|
2024-11-21 14:04 |
2020-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209487
|
6.1 |
MEDIUM
Network
|
nedi
|
nedi
|
NeDi 1.9C is vulnerable to reflected cross-site scripting. The Devices-Config.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in …
|
CWE-79
Cross-site Scripting
|
CVE-2020-15017
|
2024-11-21 14:04 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209488
|
6.1 |
MEDIUM
Network
|
nedi
|
nedi
|
NeDi 1.9C is vulnerable to reflected cross-site scripting. The Other-Converter.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15016
|
2024-11-21 14:04 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209489
|
5.9 |
MEDIUM
Network
|
trojita_project
|
trojita
|
MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to spoof SMTP servers.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-15047
|
2024-11-21 14:04 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209490
|
8.8 |
HIGH
Network
|
supermicro
|
x10drh-it_bios x10drh-it_firmware
|
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed ver…
|
CWE-352
Origin Validation Error
|
CVE-2020-15046
|
2024-11-21 14:04 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|