|
199451
|
5.4 |
MEDIUM
Network
|
wondercms
|
wondercms
|
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacker to inject the XSS payload in the Setting - Menu and each time any user will v…
|
CWE-79
Cross-site Scripting
|
CVE-2020-29469
|
2024-11-21 14:24 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199452
|
9.8 |
CRITICAL
Network
|
rocket.chat
|
rocket.chat
|
Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAML login.
|
NVD-CWE-noinfo
|
CVE-2020-29594
|
2024-11-21 14:24 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199453
|
4.8 |
MEDIUM
Network
|
opencart
|
opencart
|
OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image. An admin can upload a profile image as a malicious code using JavaScript. Whenever anyone will see the profile picture…
|
CWE-79
Cross-site Scripting
|
CVE-2020-29471
|
2024-11-21 14:24 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199454
|
4.8 |
MEDIUM
Network
|
opencart
|
opencart
|
OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Subject field of mail. This vulnerability can allow an attacker to inject the XSS payload in the Subject field of the mail and each t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-29470
|
2024-11-21 14:24 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199455
|
4.8 |
MEDIUM
Network
|
nopcommerce
|
store
|
nopCommerce Store 4.30 is affected by cross-site scripting (XSS) in the Schedule tasks name field. This vulnerability can allow an attacker to inject the XSS payload in Schedule tasks and each time a…
|
CWE-79
Cross-site Scripting
|
CVE-2020-29475
|
2024-11-21 14:24 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199456
|
9.8 |
CRITICAL
Network
|
egavilanmedia
|
egm_address_book
|
EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
|
CWE-89
SQL Injection
|
CVE-2020-29474
|
2024-11-21 14:24 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199457
|
9.8 |
CRITICAL
Network
|
egavilanmedia
|
under_construction_page_with_cpanel
|
EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrar…
|
CWE-89
SQL Injection
|
CVE-2020-29472
|
2024-11-21 14:24 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199458
|
9.8 |
CRITICAL
Network
|
urve
|
urve
|
An issue was discovered in URVE Build 24.03.2020. By using the _internal/pc/vpro.php?mac=0&ip=0&operation=0&usr=0&pass=0%3bpowershell+-c+" substring, it is possible to execute a Powershell command an…
|
CWE-78
OS Command
|
CVE-2020-29552
|
2024-11-21 14:24 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199459
|
9.1 |
CRITICAL
Network
|
urve
|
urve
|
An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown the system. Among others, the following files and scripts are also accessible: _…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-29551
|
2024-11-21 14:24 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199460
|
7.5 |
HIGH
Network
|
urve
|
urve
|
An issue was discovered in URVE Build 24.03.2020. The password of an integration user account (used for the connection of the MS Office 365 Integration Service) is stored in cleartext in configuratio…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-29550
|
2024-11-21 14:24 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|