|
198791
|
8.8 |
HIGH
Network
|
keysight
|
database_connector
|
An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could insert arbitrary JavaScript into saved macro parameters that would execute when a…
|
NVD-CWE-noinfo
|
CVE-2020-35121
|
2024-11-21 14:26 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198792
|
5.7 |
MEDIUM
Physics
|
logmein
|
lastpass
|
An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. The password authentication for unlocking can be bypassed by forcing the authent…
|
CWE-287
Improper Authentication
|
CVE-2020-35208
|
2024-11-21 14:26 |
2020-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198793
|
5.7 |
MEDIUM
Physics
|
logmein
|
lastpass
|
An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. The PIN authentication for unlocking can be bypassed by forcing the authenticati…
|
CWE-287
Improper Authentication
|
CVE-2020-35207
|
2024-11-21 14:26 |
2020-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198794
|
5.4 |
MEDIUM
Network
|
igniterealtime
|
openfire
|
Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35202
|
2024-11-21 14:26 |
2020-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198795
|
5.4 |
MEDIUM
Network
|
igniterealtime
|
openfire
|
Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp users Stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35201
|
2024-11-21 14:26 |
2020-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198796
|
6.1 |
MEDIUM
Network
|
igniterealtime
|
openfire
|
Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35200
|
2024-11-21 14:26 |
2020-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198797
|
5.4 |
MEDIUM
Network
|
igniterealtime
|
openfire
|
Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp groupchatJID Stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35199
|
2024-11-21 14:26 |
2020-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198798
|
5.3 |
MEDIUM
Network
|
awstats debian fedoraproject
|
awstats debian_linux fedora
|
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf fo…
|
CWE-22
Path Traversal
|
CVE-2020-35176
|
2024-11-21 14:26 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198799
|
5.3 |
MEDIUM
Network
|
frappe
|
frappe
|
Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.
|
NVD-CWE-noinfo
|
CVE-2020-35175
|
2024-11-21 14:26 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198800
|
5.3 |
MEDIUM
Network
|
mquery_project
|
mquery
|
lib/utils.js in mquery before 3.2.3 allows a pollution attack because a special property (e.g., __proto__) can be copied during a merge or clone operation.
|
NVD-CWE-noinfo
|
CVE-2020-35149
|
2024-11-21 14:26 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|