|
211981
|
7.5 |
HIGH
Network
|
shopware
|
shopware
|
In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-13997
|
2024-11-21 14:02 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211982
|
5.4 |
MEDIUM
Network
|
shopware
|
shopware
|
In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This leads to Persistent XSS. An uploaded image can be…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13971
|
2024-11-21 14:02 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211983
|
8.8 |
HIGH
Network
|
shopware
|
shopware
|
Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-13970
|
2024-11-21 14:02 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211984
|
9.8 |
CRITICAL
Network
|
ruckuswireless
|
unleashed_firmware
|
emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to achieve command injection via a crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R31…
|
CWE-77
Command Injection
|
CVE-2020-13919
|
2024-11-21 14:02 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211985
|
7.5 |
HIGH
Network
|
ruckuswireless
|
unleashed_firmware
|
Incorrect access control in webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to leak system information (that can be used for a jailbreak) via an unauthenticated cra…
|
NVD-CWE-noinfo
|
CVE-2020-13918
|
2024-11-21 14:02 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211986
|
9.8 |
CRITICAL
Network
|
ruckuswireless
|
unleashed_firmware
|
rkscli in Ruckus Wireless Unleashed through 200.7.10.92 allows a remote attacker to achieve command injection and jailbreak the CLI via a crafted CLI command. This affects C110, E510, H320, H510, M51…
|
CWE-77
Command Injection
|
CVE-2020-13917
|
2024-11-21 14:02 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211987
|
9.8 |
CRITICAL
Network
|
ruckuswireless
|
unleashed_firmware
|
A stack buffer overflow in webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute code via an unauthenticated crafted HTTP request. This affects C110, E510, H32…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13916
|
2024-11-21 14:02 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211988
|
7.5 |
HIGH
Network
|
ruckuswireless
|
unleashed_firmware
|
Insecure permissions in emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allow a remote attacker to overwrite admin credentials via an unauthenticated crafted HTTP request. This affec…
|
CWE-522 CWE-732
Insufficiently Protected Credentials Incorrect Permission Assignment for Critical Resource
|
CVE-2020-13915
|
2024-11-21 14:02 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211989
|
7.5 |
HIGH
Network
|
ruckuswireless
|
unleashed_firmware
|
webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to cause a denial of service (Segmentation fault) to the webserver via an unauthenticated crafted HTTP request. This…
|
NVD-CWE-noinfo
|
CVE-2020-13914
|
2024-11-21 14:02 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211990
|
6.1 |
MEDIUM
Network
|
ruckuswireless
|
unleashed_firmware
|
An XSS issue in emfd in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute JavaScript code via an unauthenticated crafted HTTP request. This affects C110, E510, H32…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13913
|
2024-11-21 14:02 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|