|
195921
|
8.8 |
HIGH
Network
|
djangoproject debian fedoraproject netapp canonical
|
django debian_linux fedora steelstore_cloud_integrated_storage ubuntu_linux
|
Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a sui…
|
CWE-89
SQL Injection
|
CVE-2020-9402
|
2024-11-21 14:40 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195922
|
9.8 |
CRITICAL
Network
|
whmcssmarters
|
web_tv_player
|
IPTV Smarters WEB TV PLAYER through 2020-02-22 allows attackers to execute OS commands by uploading a script.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-9380
|
2024-11-21 14:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195923
|
9.1 |
CRITICAL
Network
|
humaxdigital
|
hga12r-02_firmware
|
HUMAX HGA12R-02 BRGCAA 1.1.53 devices allow Session Hijacking.
|
CWE-384
Session Fixation
|
CVE-2020-9370
|
2024-11-21 14:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195924
|
9.8 |
CRITICAL
Network
|
rubetek
|
smarthome_firmware
|
Rubetek SmartHome 2020 devices use unencrypted 433 MHz communication between controllers and beacons, allowing an attacker to sniff and spoof beacon requests remotely.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-9550
|
2024-11-21 14:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195925
|
9.8 |
CRITICAL
Network
|
humaxdigital
|
hga12r-02_firmware
|
An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices. A vulnerability in the authentication functionality in the web-based interface could allow an unauthenticated remote attacker to capt…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-9477
|
2024-11-21 14:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195926
|
7.5 |
HIGH
Network
|
commscope
|
arris_tg1692a_firmware
|
ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login page and performing base64 decoding.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-9476
|
2024-11-21 14:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195927
|
7.8 |
HIGH
Local
|
codepeople
|
appointment_booking_calendar
|
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via t…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-9372
|
2024-11-21 14:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195928
|
4.8 |
MEDIUM
Network
|
codepeople
|
appointment_booking_calendar
|
Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input could allow attackers to inject arbitrary JavaScr…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9371
|
2024-11-21 14:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195929
|
5.3 |
MEDIUM
Network
|
creative-solutions
|
creative_contact_form
|
An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!. A directory traversal vulnerability resides in the filename field for uploade…
|
CWE-22
Path Traversal
|
CVE-2020-9364
|
2024-11-21 14:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195930
|
7.8 |
HIGH
Local
|
pdfresurrect_project debian
|
pdfresurrect debian_linux
|
In PDFResurrect 0.12 through 0.19, get_type in pdf.c has an out-of-bounds write via a crafted PDF document.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-9549
|
2024-11-21 14:40 |
2020-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|