|
197291
|
9.8 |
CRITICAL
Network
|
raonwiz
|
raon_k_upload
|
In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL a…
|
CWE-88
Argument Injection
|
CVE-2020-7808
|
2024-11-21 14:37 |
2020-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197292
|
6.1 |
MEDIUM
Network
|
hive
|
netius
|
netius prior to 1.17.58 is vulnerable to HTTP Request Smuggling. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Transfer encoding header parsing which could a…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-7655
|
2024-11-21 14:37 |
2020-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197293
|
6.1 |
MEDIUM
Network
|
jquery oracle netapp juniper
|
jquery peoplesoft_enterprise_peopletools snap_creator_framework cloud_backup oncommand_system_manager active_iq_unified_manager junos
|
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7656
|
2024-11-21 14:37 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197294
|
6.1 |
MEDIUM
Network
|
altools
|
alsong
|
ALSong 3.46 and earlier version contain a Document Object Model (DOM) based cross-site scripting vulnerability caused by improper validation of user input. A remote attacker could exploit this vulner…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7809
|
2024-11-21 14:37 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197295
|
5.5 |
MEDIUM
Local
|
freebsd
|
freebsd
|
In FreeBSD 12.1-STABLE before r360973, 12.1-RELEASE before p5, 11.4-STABLE before r360973, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, the FTP packet handler in libalias incorrectly calculates s…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2020-7455
|
2024-11-21 14:37 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197296
|
9.8 |
CRITICAL
Network
|
freebsd
|
freebsd
|
In FreeBSD 12.1-STABLE before r360971, 12.1-RELEASE before p5, 11.4-STABLE before r360971, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, libalias does not properly validate packet length resulting…
|
CWE-20 CWE-787
Improper Input Validation Out-of-bounds Write
|
CVE-2020-7454
|
2024-11-21 14:37 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197297
|
5.3 |
MEDIUM
Network
|
jooby
|
jooby
|
All versions before 1.6.7 and all versions after 2.0.0 inclusive and before 2.8.2 of io.jooby:jooby and org.jooby:jooby are vulnerable to Directory Traversal via two separate vectors.
|
CWE-22
Path Traversal
|
CVE-2020-7647
|
2024-11-21 14:37 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197298
|
7.8 |
HIGH
Local
|
mcafee
|
active_response
|
Privilege Escalation vulnerability in McAfee Active Response (MAR) for Mac prior to 2.4.3 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been…
|
CWE-269
Improper Privilege Management
|
CVE-2020-7291
|
2024-11-21 14:37 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197299
|
9.8 |
CRITICAL
Network
|
infomark
|
iml500_firmware iml520_firmware
|
An issue was discovered on KT Slim egg IML500 (R7283, R8112, R8424) and IML520 (R8112, R8368, R8411) wifi device. This issue is a command injection allowing attackers to execute arbitrary OS commands.
|
CWE-78
OS Command
|
CVE-2020-7805
|
2024-11-21 14:37 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197300
|
8.8 |
HIGH
Network
|
imgtech
|
zoneplayer
|
IMGTech Co,Ltd ZInsX.ocx ActiveX Control in Zoneplayer 2.0.1.3, version 2.0.1.4 and prior versions on Windows. File Donwload vulnerability in ZInsX.ocx of IMGTech Co,Ltd Zoneplayer allows attacker to…
|
NVD-CWE-noinfo
|
CVE-2020-7803
|
2024-11-21 14:37 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|