|
208361
|
9.8 |
CRITICAL
Network
|
troglobit
|
uftpd
|
An unauthenticated stack-based buffer overflow vulnerability in common.c's handle_PORT in uftpd FTP server versions 2.10 and earlier can be abused to cause a crash and could potentially lead to remot…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-20276
|
2024-11-21 14:11 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208362
|
6.1 |
MEDIUM
Network
|
flexmonster
|
pivot_table_\&_charts
|
Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table & Charts 2.7.17.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20142
|
2024-11-21 14:11 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208363
|
6.1 |
MEDIUM
Network
|
flexmonster
|
pivot_table_\&_charts
|
Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20141
|
2024-11-21 14:11 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208364
|
6.1 |
MEDIUM
Network
|
flexmonster
|
pivot_table_\&_charts
|
Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20140
|
2024-11-21 14:11 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208365
|
6.1 |
MEDIUM
Network
|
flexmonster
|
pivot_table_\&_charts
|
Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20139
|
2024-11-21 14:11 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208366
|
6.1 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
Cross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20138
|
2024-11-21 14:11 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208367
|
9.8 |
CRITICAL
Network
|
newpk_project
|
newpk
|
SQL Injection vulnerability in NewPK 1.1 via the title parameter to admin\newpost.php.
|
CWE-89
SQL Injection
|
CVE-2020-20189
|
2024-11-21 14:11 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208368
|
9.8 |
CRITICAL
Network
|
liftoffsoftware
|
gateone
|
GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.
|
CWE-78
OS Command
|
CVE-2020-20184
|
2024-11-21 14:11 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208369
|
7.5 |
HIGH
Network
|
zyxel
|
p1302-t10_v3_firmware
|
Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier allows attackers to gain privileges and access certain admin pages.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-20183
|
2024-11-21 14:11 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208370
|
9.8 |
CRITICAL
Network
|
quantconnect
|
lean
|
QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-20136
|
2024-11-21 14:11 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|