|
209091
|
6.1 |
MEDIUM
Network
|
mibew
|
messenger
|
Mibew Messenger before 3.2.7 allows XSS via a crafted user name.
|
CWE-79
Cross-site Scripting
|
CVE-2020-17476
|
2024-11-21 14:08 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209092
|
7.2 |
HIGH
Network
|
flatcore
|
flatcore
|
flatCore before 1.5.7 allows upload and execution of a .php file by an admin.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-17452
|
2024-11-21 14:08 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209093
|
4.8 |
MEDIUM
Network
|
flatcore
|
flatcore
|
flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title, page_content, or page_extracontent parameter, or the acp/acp.php?tn=system&sub…
|
CWE-79
Cross-site Scripting
|
CVE-2020-17451
|
2024-11-21 14:08 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209094
|
7.8 |
HIGH
Local
|
microsoft
|
python_extension
|
Visual Studio Code Python Extension Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2020-17163
|
2024-11-21 14:07 |
2023-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209095
|
8.6 |
HIGH
Local
|
lilypond
|
lilypond
|
LilyPond before 2.24 allows attackers to bypass the -dsafe protection mechanism via output-def-lookup or output-def-scope, as demonstrated by dangerous Scheme code in a .ly file that causes arbitrary…
|
CWE-863
Incorrect Authorization
|
CVE-2020-17354
|
2024-11-21 14:07 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209096
|
6.7 |
MEDIUM
Local
|
bbraun
|
datamodule_compactplus spacecom
|
A vulnerability in the configuration import mechanism of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with com…
|
-
|
CVE-2020-16238
|
2024-11-21 14:07 |
2022-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209097
|
9.8 |
CRITICAL
Network
|
telosalliance
|
z\/ip_one_firmware
|
A directory traversal vulnerability on Telos Z/IP One devices through 4.0.0r grants an unauthenticated individual root level access to the device's file system. This can be used to identify configura…
|
CWE-22
Path Traversal
|
CVE-2020-17383
|
2024-11-21 14:07 |
2022-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209098
|
6.8 |
MEDIUM
Adjacent
|
ti
|
real-time_operating_system z-stack 15.4-stack openthread easylink ble5-stack dynamic_multi-protocal_manager
|
TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile. A LTK can be an unauthenticated-and-no-MITM-protection key created by Just Works or an authenticated-and-MITM-protection key c…
|
CWE-863
Incorrect Authorization
|
CVE-2020-16630
|
2024-11-21 14:07 |
2021-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209099
|
7.5 |
HIGH
Network
|
crestron
|
dm-nvx-dir-80_firmware dm-nvx-dir-160_firmware dm-nvx-dir-ent_firmware
|
On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthenticated WebSocket request.
|
CWE-287
Improper Authentication
|
CVE-2020-16839
|
2024-11-21 14:07 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209100
|
5.4 |
MEDIUM
Network
|
dedecms
|
dedecms
|
A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remote arbitrary code via the keyword parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-16632
|
2024-11-21 14:07 |
2021-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|