|
197811
|
6.1 |
MEDIUM
Network
|
chiyu-t
|
bf-430_firmware
|
Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cgi TF_submask field.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8839
|
2024-11-21 14:39 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197812
|
7.5 |
HIGH
Network
|
iktm
|
bearftp
|
Improper connection handling in the base connection handler in IKTeam BearFTP before v0.3.1 allows a remote attacker to achieve denial of service via a Slowloris approach by sending a large volume of…
|
CWE-20
Improper Input Validation
|
CVE-2020-8815
|
2024-11-21 14:39 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197813
|
7.3 |
HIGH
Network
|
istio redhat
|
istio openshift_service_mesh
|
Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact-path matching logic can allow unauthorized access…
|
CWE-287
Improper Authentication
|
CVE-2020-8595
|
2024-11-21 14:39 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197814
|
6.5 |
MEDIUM
Network
|
misp
|
misp
|
An issue was discovered in MISP before 2.4.121. ACLs for discussion threads were mishandled in app/Controller/ThreadsController.php and app/Model/Thread.php.
|
NVD-CWE-noinfo
|
CVE-2020-8894
|
2024-11-21 14:39 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197815
|
7.5 |
HIGH
Network
|
misp
|
misp
|
An issue was discovered in MISP before 2.4.121. The Galaxy view contained an incorrectly sanitized search string in app/View/Galaxies/view.ctp.
|
NVD-CWE-noinfo
|
CVE-2020-8893
|
2024-11-21 14:39 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197816
|
8.1 |
HIGH
Network
|
misp
|
misp
|
An issue was discovered in MISP before 2.4.121. It did not consider the HTTP PUT method when trying to block a brute-force series of invalid requests.
|
NVD-CWE-noinfo
|
CVE-2020-8892
|
2024-11-21 14:39 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197817
|
5.9 |
MEDIUM
Network
|
misp
|
misp
|
An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force series of invalid requests.
|
NVD-CWE-noinfo
|
CVE-2020-8891
|
2024-11-21 14:39 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197818
|
5.9 |
MEDIUM
Network
|
misp
|
misp
|
An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and the machine hosting the database) when trying to block a brute-force series of …
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2020-8890
|
2024-11-21 14:39 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197819
|
7.5 |
HIGH
Network
|
xnau
|
participants_database
|
participants-database.php in the Participants Database plugin 1.9.5.5 and previous versions for WordPress has a time-based SQL injection vulnerability via the ascdesc, list_filter_count, or sortBy pa…
|
CWE-89
SQL Injection
|
CVE-2020-8596
|
2024-11-21 14:39 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197820
|
8.8 |
HIGH
Network
|
testlink
|
testlink
|
An issue was discovered in TestLink 1.9.19. The relation_type parameter of the lib/requirements/reqSearch.php endpoint is vulnerable to authenticated SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2020-8841
|
2024-11-21 14:39 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|