|
196321
|
5.4 |
MEDIUM
Network
|
fiserv
|
accurate_reconciliation
|
Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the Source or Destination field of the Configuration Manager (Configuration Parameter Translation) page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8951
|
2024-11-21 14:39 |
2020-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196322
|
8.1 |
HIGH
Network
|
gurux
|
device_language_message_specification_director
|
An issue was discovered in Gurux GXDLMS Director through 8.5.1905.1301. When downloading OBIS codes, it does not verify that the downloaded files are actual OBIS codes and doesn't check for path trav…
|
CWE-22
Path Traversal
|
CVE-2020-8810
|
2024-11-21 14:39 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196323
|
8.1 |
HIGH
Network
|
gurux
|
device_language_message_specification_director
|
Gurux GXDLMS Director prior to 8.5.1905.1301 downloads updates to add-ins and OBIS code over an unencrypted HTTP connection. A man-in-the-middle attacker can prompt the user to download updates by mo…
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-8809
|
2024-11-21 14:39 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196324
|
6.1 |
MEDIUM
Network
|
wpjobboard
|
wpjobboard
|
The WPJobBoard plugin 5.5.3 for WordPress allows Persistent XSS via the Add Job form, as demonstrated by title and Description.
|
CWE-79
Cross-site Scripting
|
CVE-2020-9019
|
2024-11-21 14:39 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196325
|
5.3 |
MEDIUM
Network
|
litecart
|
litecart
|
LiteCart through 2.2.1 allows admin/?app=users&doc=edit_user CSRF to add a user.
|
CWE-352
Origin Validation Error
|
CVE-2020-9018
|
2024-11-21 14:39 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196326
|
5.4 |
MEDIUM
Network
|
blackboard
|
blackboard_learn
|
Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web script via the Tile widget in the People Tool profile editor.
|
CWE-79
Cross-site Scripting
|
CVE-2020-9008
|
2024-11-21 14:39 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196327
|
8.0 |
HIGH
Network
|
litecart
|
litecart
|
LiteCart through 2.2.1 allows CSV injection via a customer's profile.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-9017
|
2024-11-21 14:39 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196328
|
9.8 |
CRITICAL
Network
|
opensmtpd canonical fedoraproject debian
|
opensmtpd ubuntu_linux fedora debian_linux
|
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTP…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-8794
|
2024-11-21 14:39 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196329
|
4.7 |
MEDIUM
Local
|
opensmtpd fedoraproject canonical
|
opensmtpd fedora ubuntu_linux
|
OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offl…
|
CWE-426 CWE-367
Untrusted Search Path Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2020-8793
|
2024-11-21 14:39 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196330
|
8.1 |
HIGH
Network
|
cardgate
|
cardgate_payments
|
An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in the IPN callback processing function in cardgate/cardgate.php allows an attack…
|
CWE-346
Origin Validation Error
|
CVE-2020-8819
|
2024-11-21 14:39 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|