|
197081
|
5.3 |
MEDIUM
Network
|
iblsoft
|
online_weather
|
IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COOKIE cookie.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-9407
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197082
|
9.8 |
CRITICAL
Network
|
iblsoft
|
online_weather
|
IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.
|
CWE-94
Code Injection
|
CVE-2020-9406
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197083
|
6.1 |
MEDIUM
Network
|
iblsoft
|
online_weather
|
IBL Online Weather before 4.3.5a allows unauthenticated reflected XSS via the redirect page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-9405
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197084
|
9.8 |
CRITICAL
Network
|
ispconfig
|
ispconfig
|
ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2020-9398
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197085
|
8.8 |
HIGH
Network
|
supsystic
|
pricing_table_by_supsystic
|
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-9394
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197086
|
6.1 |
MEDIUM
Network
|
supsystic
|
pricing_table_by_supsystic
|
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-9393
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197087
|
6.5 |
MEDIUM
Network
|
mitel
|
micontact_center_business
|
The Software Development Kit of the MiContact Center Business with Site Based Security 8.0 through 9.0.1.0 before KB496276 allows an authenticated user to access sensitive information. A successful e…
|
NVD-CWE-noinfo
|
CVE-2020-9379
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197088
|
5.5 |
MEDIUM
Local
|
linux fedoraproject netapp
|
linux_kernel fedora cloud_backup steelstore_cloud_integrated_storage data_availability_services solidfire hci_management_node active_iq_unified_manager h410c_firmware
|
An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-9391
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197089
|
4.8 |
MEDIUM
Network
|
10web
|
photo_gallery
|
Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploitation of this vulnerability would allow a authenticated admin user to inject arb…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9335
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197090
|
5.4 |
MEDIUM
Network
|
enviragallery
|
envira_gallery
|
A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitation of this vulnerability would allow a authenticated low-privileged user to inje…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9334
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|