|
197401
|
8.8 |
HIGH
Network
|
zend
|
zendto
|
ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2020-8985
|
2024-11-21 14:39 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197402
|
7.5 |
HIGH
Network
|
zend
|
zendto
|
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.
|
CWE-346
Origin Validation Error
|
CVE-2020-8984
|
2024-11-21 14:39 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197403
|
9.8 |
CRITICAL
Network
|
quest
|
foglight_evolve
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve 9.0.0. Authentication is not required to exploit this vulnerability. The specif…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-8868
|
2024-11-21 14:39 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197404
|
6.5 |
MEDIUM
Network
|
horde debian
|
groupware horde_form debian_linux
|
This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. The…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-8866
|
2024-11-21 14:39 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197405
|
6.3 |
MEDIUM
Network
|
horde debian
|
groupware debian_linux
|
This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. Th…
|
CWE-22
Path Traversal
|
CVE-2020-8865
|
2024-11-21 14:39 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197406
|
7.5 |
HIGH
Network
|
psi
|
electronic_logbook
|
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ELOG Electronic Logbook 3.1.4-283534d. Authentication is not required to exploit this v…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-8859
|
2024-11-21 14:39 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197407
|
8.8 |
HIGH
Adjacent
|
dlink
|
dir-878_firmware dir-882_firmware dir-867_firmware
|
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not re…
|
CWE-697
Incorrect Comparison
|
CVE-2020-8864
|
2024-11-21 14:39 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197408
|
8.8 |
HIGH
Adjacent
|
dlink
|
dir-878_firmware dir-882_firmware dir-867_firmware
|
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not re…
|
CWE-287
Improper Authentication
|
CVE-2020-8863
|
2024-11-21 14:39 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197409
|
5.5 |
MEDIUM
Local
|
parallels
|
parallels_desktop
|
This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute low-privileged code…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-8876
|
2024-11-21 14:39 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197410
|
6.4 |
MEDIUM
Adjacent
|
zohocorp
|
manageengine_assetexplorer
|
An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent n…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-8838
|
2024-11-21 14:39 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|