|
200931
|
6.1 |
MEDIUM
Network
|
projectworlds
|
travel_management_system
|
XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via the name field
|
CWE-79
Cross-site Scripting
|
CVE-2020-29205
|
2024-11-21 14:23 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200932
|
5.4 |
MEDIUM
Network
|
deskpro
|
deskpro
|
Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to an account takeover via custom email templates.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28722
|
2024-11-21 14:23 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200933
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite 7.10.4 and earlier allows XSS via crafted content to reach an undocumented feature, such as 
|
CVE-2020-28943
|
2024-11-21 14:23 |
2021-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200936
|
7.5 |
HIGH
Network
|
abus
|
secvest_wireless_alarm_system_fuaa50000_firmware
|
The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can use this vulnerability to obtain sensitive inform…
|
CWE-287
Improper Authentication
|
CVE-2020-28973
|
2024-11-21 14:23 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200937
|
5.3 |
MEDIUM
Network
|
resourcexpress
|
resourcexpress
|
In QED ResourceXpress through 4.9k, a large numeric or alphanumeric value submitted in specific URL parameters causes a server error in script execution due to insufficient input validation.
|
CWE-20
Improper Input Validation
|
CVE-2020-28898
|
2024-11-21 14:23 |
2021-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200938
|
9.8 |
CRITICAL
Network
|
monitorr
|
monitorr
|
An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows an unauthorized person to create valid credentials.
|
CWE-863
Incorrect Authorization
|
CVE-2020-28872
|
2024-11-21 14:23 |
2021-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200939
|
8.8 |
HIGH
Adjacent
|
askey
|
rtf3505vw-n1_br_sv_g000_r3505vwn1001_s32_7_firmware
|
Askey Fiber Router RTF3505VW-N1 BR_SV_g000_R3505VWN1001_s32_7 devices allow Remote Code Execution and retrieval of admin credentials to log into the Dashboard or login via SSH, leading to code execut…
|
CWE-78
OS Command
|
CVE-2020-28695
|
2024-11-21 14:23 |
2021-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200940
|
7.5 |
HIGH
Network
|
fluxbb
|
fluxbb
|
Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user login form. When a long password is sent, the password hashing process will res…
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2020-28873
|
2024-11-21 14:23 |
2021-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|