|
210591
|
5.4 |
MEDIUM
Network
|
nedi
|
nedi
|
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Routes.php rtr parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15030
|
2024-11-21 14:04 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210592
|
5.4 |
MEDIUM
Network
|
nedi
|
nedi
|
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Assets-Management.php sn parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15029
|
2024-11-21 14:04 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210593
|
5.4 |
MEDIUM
Network
|
nedi
|
nedi
|
NeDi 1.9C is vulnerable to a cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Map.php xo parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15028
|
2024-11-21 14:04 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210594
|
5.4 |
MEDIUM
Network
|
nedi
|
nedi
|
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Reports-Devices.php page st[] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15037
|
2024-11-21 14:04 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210595
|
5.4 |
MEDIUM
Network
|
nedi
|
nedi
|
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Linked.php dv parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15036
|
2024-11-21 14:04 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210596
|
6.8 |
MEDIUM
Network
|
electronjs
|
electron
|
In Electron before versions 6.1.1, 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass, meaning that code running in the main world context in the renderer can reach into the isolated…
|
NVD-CWE-Other
|
CVE-2020-15096
|
2024-11-21 14:04 |
2020-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210597
|
6.5 |
MEDIUM
Network
|
tendermint
|
tendermint
|
TenderMint from version 0.33.0 and before version 0.33.6 allows block proposers to include signatures for the wrong block. This may happen naturally if you start a network, have it run for some time …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-15091
|
2024-11-21 14:04 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210598
|
6.1 |
MEDIUM
Network
|
prestashop
|
prestashop
|
In PrestaShop from version 1.7.0.0 and before version 1.7.6.6, if a target sends a corrupted file, it leads to a reflected XSS. The problem is fixed in 1.7.6.6
|
CWE-79
Cross-site Scripting
|
CVE-2020-15083
|
2024-11-21 14:04 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210599
|
8.8 |
HIGH
Network
|
prestashop
|
prestashop
|
In PrestaShop from version 1.6.0.1 and before version 1.7.6.6, the dashboard allows rewriting all configuration variables. The problem is fixed in 1.7.6.6
|
NVD-CWE-Other
|
CVE-2020-15082
|
2024-11-21 14:04 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210600
|
5.3 |
MEDIUM
Network
|
prestashop
|
prestashop
|
In PrestaShop from version 1.5.0.0 and before 1.7.6.6, there is information exposure in the upload directory. The problem is fixed in version 1.7.6.6. A possible workaround is to add an empty index.p…
|
CWE-200
Information Exposure
|
CVE-2020-15081
|
2024-11-21 14:04 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|