|
196121
|
7.5 |
HIGH
Network
|
solarwinds
|
n-central
|
SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive inf…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-7984
|
2024-11-21 14:38 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196122
|
9.8 |
CRITICAL
Network
|
rubygeocoder
|
geocoder
|
sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data.
|
CWE-89
SQL Injection
|
CVE-2020-7981
|
2024-11-21 14:38 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196123
|
9.8 |
CRITICAL
Network
|
intelliantech
|
aptus_web
|
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. NOTE: a valid sid cookie for a login to the intelli…
|
CWE-78
OS Command
|
CVE-2020-7980
|
2024-11-21 14:38 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196124
|
5.3 |
MEDIUM
Network
|
mirumee
|
saleor
|
An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user ID and consequently…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-7964
|
2024-11-21 14:38 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196125
|
9.8 |
CRITICAL
Network
|
plone
|
plone
|
A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission.
|
NVD-CWE-noinfo
|
CVE-2020-7941
|
2024-11-21 14:38 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196126
|
7.5 |
HIGH
Network
|
plone
|
plone
|
Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.
|
CWE-521
Weak Password Requirements
|
CVE-2020-7940
|
2024-11-21 14:38 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196127
|
8.8 |
HIGH
Network
|
plone
|
plone
|
SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)
|
CWE-89
SQL Injection
|
CVE-2020-7939
|
2024-11-21 14:38 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196128
|
8.8 |
HIGH
Network
|
plone
|
plone
|
plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.
|
NVD-CWE-noinfo
|
CVE-2020-7938
|
2024-11-21 14:38 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196129
|
5.4 |
MEDIUM
Network
|
plone
|
plone
|
An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a certain privilege level to insert JavaScript that will be executed when other users access the site.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7937
|
2024-11-21 14:38 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196130
|
6.1 |
MEDIUM
Network
|
plone
|
plone
|
An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redire…
|
CWE-601
Open Redirect
|
CVE-2020-7936
|
2024-11-21 14:38 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|