|
209601
|
6.5 |
MEDIUM
Network
|
maxum
|
rumpus
|
An issue was discovered in Maxum Rumpus before 8.2.12 on macOS. Authenticated users can perform a path traversal using double escaped characters, enabling read access to arbitrary files on the server.
|
CWE-22
Path Traversal
|
CVE-2020-12737
|
2024-11-21 14:00 |
2020-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209602
|
5.5 |
MEDIUM
Local
|
avira
|
free_antivirus
|
Avira Free Antivirus through 15.0.2005.1866 allows local users to discover user credentials. The functions of the executable file Avira.PWM.NativeMessaging.exe are aimed at collecting credentials sto…
|
NVD-CWE-noinfo
|
CVE-2020-12680
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209603
|
9.8 |
CRITICAL
Network
|
domainmod
|
domainmod
|
reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.
|
CWE-331
Insufficient Entropy
|
CVE-2020-12735
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209604
|
9.8 |
CRITICAL
Network
|
vbulletin
|
vbulletin
|
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.
|
CWE-89 CWE-306
SQL Injection Missing Authentication for Critical Function
|
CVE-2020-12720
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209605
|
7.2 |
HIGH
Network
|
wso2
|
identity_server_analytics identity_server identity_server_as_key_manager enterprise_integrator api_microgateway api_manager_analytics api_manager
|
XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, API Microgateway 2.2.0, Enterprise Integrator 6.4.0…
|
CWE-611
XXE
|
CVE-2020-12719
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209606
|
5.4 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comment feature. The protection mechanism can be bypass…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12718
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209607
|
6.1 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to downloads/downloads.php or article.php. N…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12708
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209608
|
6.1 |
MEDIUM
Network
|
lepton-cms
|
lepton_cms
|
An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elements. A malicious a…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12707
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209609
|
5.4 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12706
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209610
|
6.1 |
MEDIUM
Network
|
lepton-cms
|
leptoncms
|
Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12705
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|