|
196371
|
4.3 |
MEDIUM
Network
|
aishu
|
anyshare_cloud
|
AnyShare Cloud 6.0.9 allows authenticated directory traversal to read files, as demonstrated by the interface/downloadwithpath/downloadfile/?filepath=/etc/passwd URI.
|
CWE-22
Path Traversal
|
CVE-2020-8996
|
2024-11-21 14:39 |
2020-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196372
|
5.4 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms
|
The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8594
|
2024-11-21 14:39 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196373
|
7.4 |
HIGH
Network
|
istio
|
istio
|
An issue was discovered in Istio 1.3 through 1.3.6. Under certain circumstances, it is possible to bypass a specifically configured Mixer policy. Istio-proxy accepts the x-istio-attributes header at …
|
CWE-20
Improper Input Validation
|
CVE-2020-8843
|
2024-11-21 14:39 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196374
|
9.0 |
CRITICAL
Network
|
progess progress
|
moveit_transfer
|
In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately sanitize malicious input, which could allow an authenticated attacker to execut…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8612
|
2024-11-21 14:39 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196375
|
8.8 |
HIGH
Network
|
moxa
|
mgate_5105-mb-eip_firmware mgate_5105-mb-eip-t_firmware
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Moxa MGate 5105-MB-EIP firmware version 4.1. Authentication is required to exploit this vulnerability…
|
CWE-78
OS Command
|
CVE-2020-8858
|
2024-11-21 14:39 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196376
|
7.8 |
HIGH
Local
|
foxitsoftware
|
reader phantompdf
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the targ…
|
CWE-416
Use After Free
|
CVE-2020-8857
|
2024-11-21 14:39 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196377
|
7.8 |
HIGH
Local
|
foxitsoftware
|
reader phantompdf
|
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25608. User interaction is required to exploit this vulnerability in that the t…
|
CWE-416
Use After Free
|
CVE-2020-8856
|
2024-11-21 14:39 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196378
|
7.8 |
HIGH
Local
|
foxitsoftware
|
reader phantompdf
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.2947. User interaction is required to exploit this vulnerability in that the t…
|
CWE-416
Use After Free
|
CVE-2020-8855
|
2024-11-21 14:39 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196379
|
7.8 |
HIGH
Local
|
foxitsoftware
|
reader phantompdf
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-8854
|
2024-11-21 14:39 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196380
|
7.8 |
HIGH
Local
|
foxitsoftware
|
reader phantompdf
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-8853
|
2024-11-21 14:39 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|