|
198231
|
9.8 |
CRITICAL
Network
|
tp-link
|
tl-wr840n_firmware
|
oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web interface (an IP address field) is used directly for…
|
CWE-78
OS Command
|
CVE-2020-36178
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198232
|
9.8 |
CRITICAL
Network
|
wolfssl
|
wolfssl
|
RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certain relationships between key size and digest size.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-36177
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198233
|
7.5 |
HIGH
Network
|
ithemes
|
ithemes_security
|
The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.
|
CWE-287
Improper Authentication
|
CVE-2020-36176
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198234
|
5.3 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms
|
The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.
|
CWE-20
Improper Input Validation
|
CVE-2020-36175
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198235
|
6.5 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms
|
The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.
|
CWE-352
Origin Validation Error
|
CVE-2020-36174
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198236
|
5.3 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms
|
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2020-36173
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198237
|
6.1 |
MEDIUM
Network
|
advancedcustomfields
|
advanced_custom_fields
|
The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-36172
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198238
|
6.1 |
MEDIUM
Network
|
elementor
|
website_builder
|
The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.
|
CWE-79
Cross-site Scripting
|
CVE-2020-36171
|
2024-11-21 14:28 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198239
|
5.3 |
MEDIUM
Network
|
ultimatemember
|
ultimate_member
|
The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms.
|
NVD-CWE-noinfo
|
CVE-2020-36170
|
2024-11-21 14:28 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198240
|
8.8 |
HIGH
Local
|
veritas
|
netbackup opscenter
|
An issue was discovered in Veritas NetBackup through 8.3.0.1 and OpsCenter through 8.3.0.1. Processes using OpenSSL attempt to load and execute libraries from paths that do not exist by default on th…
|
NVD-CWE-noinfo
|
CVE-2020-36169
|
2024-11-21 14:28 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|