|
197741
|
9.8 |
CRITICAL
Network
|
dlink
|
dsl-2640b_firmware
|
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A cfm UDP service listening on port 65002 allows remote, unauthenticated exfiltration of administrative credentials.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-9275
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197742
|
6.1 |
MEDIUM
Network
|
zulip
|
zulip_server
|
Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.
|
CWE-79
Cross-site Scripting
|
CVE-2020-9445
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197743
|
6.1 |
MEDIUM
Network
|
zulip
|
zulip_server
|
Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality.
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-9444
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197744
|
8.8 |
HIGH
Network
|
microfocus
|
enterprise_developer enterprise_server
|
Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patch Update 16, and version 5.0 Patch Update 6. The v…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-9523
|
2024-11-21 14:40 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197745
|
7.5 |
HIGH
Network
|
silverstripe
|
silverstripe
|
In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed uploa…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-9280
|
2024-11-21 14:40 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197746
|
8.8 |
HIGH
Network
|
subex
|
roc_partner_settlement
|
An Insecure Direct Object Reference (IDOR) vulnerability in the Change Password feature of Subex ROC Partner Settlement 10.5 allows remote authenticated users to achieve account takeover via manipula…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-9384
|
2024-11-21 14:40 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197747
|
5.4 |
MEDIUM
Network
|
octech
|
oempro
|
Octech Oempro 4.7 through 4.11 allow stored XSS by an authenticated user. The FolderName parameter of the Media.CreateFolder command is vulnerable.
|
CWE-79
Cross-site Scripting
|
CVE-2020-9461
|
2024-11-21 14:40 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197748
|
5.4 |
MEDIUM
Network
|
octech
|
oempro
|
Octech Oempro 4.7 through 4.11 allow XSS by an authenticated user. The parameter CampaignName in Campaign.Create is vulnerable.
|
CWE-79
Cross-site Scripting
|
CVE-2020-9460
|
2024-11-21 14:40 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197749
|
8.8 |
HIGH
Network
|
rubrik
|
cdm
|
An issue was discovered in Rubrik 5.0.3-2296. An OS command injection vulnerability allows an authenticated attacker to remotely execute arbitrary code on Rubrik-managed systems.
|
CWE-78
OS Command
|
CVE-2020-9478
|
2024-11-21 14:40 |
2020-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197750
|
4.9 |
MEDIUM
Network
|
dahuasecurity
|
sd6al_firmware sd5a_firmware sd1a_firmware ptz1a_firmware sd50_firmware sd52c_firmware ipc-hx5842h_firmware ipc-hx7842h_firmware ipc-hx2xxx_firmware ipc-hxxx5x4x_firmware
|
Some products of Dahua have Denial of Service vulnerabilities. After the successful login of the legal account, the attacker sends a specific log query command, which may cause the device to go down.
|
NVD-CWE-noinfo
|
CVE-2020-9500
|
2024-11-21 14:40 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|