|
210221
|
6.1 |
MEDIUM
Network
|
algolplus
|
advanced_order_export_for_woocommerce
|
A cross-site scripting (XSS) vulnerability in the AlgolPlus Advanced Order Export For WooCommerce plugin 3.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the vie…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11727
|
2024-11-21 13:58 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210222
|
6.1 |
MEDIUM
Network
|
zimbra
|
zimbra
|
A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-Mail message or calendar invite to execute arbitrary JavaScript. The attack requ…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11737
|
2024-11-21 13:58 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210223
|
8.1 |
HIGH
Network
|
teampass
|
teampass
|
Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPass administrator and read/modify all passwords via…
|
CWE-862
Missing Authorization
|
CVE-2020-11671
|
2024-11-21 13:58 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210224
|
7.5 |
HIGH
Network
|
microfocus
|
verastream_host_integrator
|
Information disclosure vulnerability in Micro Focus Verastream Host Integrator (VHI) product, affecting versions earlier than 7.8 Update 1 (7.8.49 or 7.8.0.49). The vulnerability allows an unauthenti…
|
NVD-CWE-noinfo
|
CVE-2020-11842
|
2024-11-21 13:58 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210225
|
6.5 |
MEDIUM
Network
|
saltstack opensuse debian canonical blackberry vmware
|
salt leap debian_linux ubuntu_linux workspaces_server application_remote_collector
|
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods …
|
CWE-22
Path Traversal
|
CVE-2020-11652
|
2024-11-21 13:58 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210226
|
9.8 |
CRITICAL
Network
|
saltstack opensuse debian canonical vmware
|
salt leap debian_linux ubuntu_linux application_remote_collector
|
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access…
|
NVD-CWE-Other
|
CVE-2020-11651
|
2024-11-21 13:58 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210227
|
8.8 |
HIGH
Network
|
opmantek
|
open-audit
|
An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-11943
|
2024-11-21 13:58 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210228
|
9.8 |
CRITICAL
Network
|
opmantek
|
open-audit
|
An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections.
|
CWE-89
SQL Injection
|
CVE-2020-11942
|
2024-11-21 13:58 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210229
|
8.8 |
HIGH
Adjacent
|
cerner
|
medico
|
Cerner medico 26.00 has a Local Buffer Overflow (issue 3 of 3).
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-11677
|
2024-11-21 13:58 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210230
|
8.8 |
HIGH
Adjacent
|
cerner
|
medico
|
Cerner medico 26.00 has a Local Buffer Overflow (issue 2 of 3).
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-11676
|
2024-11-21 13:58 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|