|
208741
|
8.8 |
HIGH
Network
|
emerson
|
wireless_1420_gateway_firmware
|
Emerson Smart Wireless Gateway 1420 4.6.59 allows non-privileged users (such as the default account 'maint') to perform administrative tasks by sending specially crafted HTTP requests to the applicat…
|
NVD-CWE-Other
|
CVE-2020-19417
|
2024-11-21 14:09 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208742
|
6.1 |
MEDIUM
Network
|
carrier
|
webctrl_system
|
Automated Logic Corporation (ALC) WebCTRL System 6.5 and prior allows remote attackers to execute any JavaScript code via a XSS payload for the first parameter in a GET request.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19762
|
2024-11-21 14:09 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208743
|
7.8 |
HIGH
Local
|
aida64
|
aida64
|
Buffer overflow in FinalWire Ltd AIDA64 Engineer 6.00.5100 allows attackers to execute arbitrary code by creating a crafted input that will overwrite the SEH handler.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-19513
|
2024-11-21 14:09 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208744
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19364
|
2024-11-21 14:09 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208745
|
6.5 |
MEDIUM
Network
|
vtiger
|
vtiger_crm
|
Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.
|
CWE-200
Information Exposure
|
CVE-2020-19363
|
2024-11-21 14:09 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208746
|
6.1 |
MEDIUM
Network
|
vtiger
|
vtiger_crm
|
Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-part…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19362
|
2024-11-21 14:09 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208747
|
6.1 |
MEDIUM
Network
|
medintux
|
medintux
|
Reflected XSS in Medintux v2.16.000 CCAM.php by manipulating the mot1 parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web …
|
CWE-79
Cross-site Scripting
|
CVE-2020-19361
|
2024-11-21 14:09 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208748
|
7.5 |
HIGH
Network
|
fhem
|
fhem
|
Local file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a file, which can lead to sensitive information disclosure.
|
CWE-22
Path Traversal
|
CVE-2020-19360
|
2024-11-21 14:09 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208749
|
8.8 |
HIGH
Network
|
draytek
|
vigor2960_firmware
|
DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.
|
CWE-78
OS Command
|
CVE-2020-19664
|
2024-11-21 14:09 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208750
|
9.8 |
CRITICAL
Network
|
phpshe
|
phpshe
|
PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.
|
CWE-89
SQL Injection
|
CVE-2020-19165
|
2024-11-21 14:09 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|