|
198251
|
6.1 |
MEDIUM
Network
|
gluu
|
gluu_server
|
A cross-site scripting (XSS) vulnerability in the Import People functionality in Gluu Identity Configuration 4.0 allows remote attackers to inject arbitrary web script or HTML via the filename parame…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9012
|
2024-11-21 14:39 |
2020-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198252
|
5.4 |
MEDIUM
Network
|
codologic
|
codoforum
|
Codoforum 4.8.8 allows self-XSS via the title of a new topic.
|
CWE-79
Cross-site Scripting
|
CVE-2020-9007
|
2024-11-21 14:39 |
2020-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198253
|
8.8 |
HIGH
Adjacent
|
abbott
|
freestyle_libre_firmware
|
Older generation Abbott FreeStyle Libre sensors allow remote attackers within close proximity to enable write access to memory via a specific NFC unlock command. NOTE: The vulnerability is not presen…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-8997
|
2024-11-21 14:39 |
2020-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198254
|
4.3 |
MEDIUM
Network
|
aishu
|
anyshare_cloud
|
AnyShare Cloud 6.0.9 allows authenticated directory traversal to read files, as demonstrated by the interface/downloadwithpath/downloadfile/?filepath=/etc/passwd URI.
|
CWE-22
Path Traversal
|
CVE-2020-8996
|
2024-11-21 14:39 |
2020-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198255
|
5.4 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms
|
The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8594
|
2024-11-21 14:39 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198256
|
7.4 |
HIGH
Network
|
istio
|
istio
|
An issue was discovered in Istio 1.3 through 1.3.6. Under certain circumstances, it is possible to bypass a specifically configured Mixer policy. Istio-proxy accepts the x-istio-attributes header at …
|
CWE-20
Improper Input Validation
|
CVE-2020-8843
|
2024-11-21 14:39 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198257
|
9.0 |
CRITICAL
Network
|
progess progress
|
moveit_transfer
|
In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately sanitize malicious input, which could allow an authenticated attacker to execut…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8612
|
2024-11-21 14:39 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198258
|
8.8 |
HIGH
Network
|
moxa
|
mgate_5105-mb-eip_firmware mgate_5105-mb-eip-t_firmware
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Moxa MGate 5105-MB-EIP firmware version 4.1. Authentication is required to exploit this vulnerability…
|
CWE-78
OS Command
|
CVE-2020-8858
|
2024-11-21 14:39 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198259
|
7.8 |
HIGH
Local
|
foxitsoftware
|
reader phantompdf
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the targ…
|
CWE-416
Use After Free
|
CVE-2020-8857
|
2024-11-21 14:39 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198260
|
7.8 |
HIGH
Local
|
foxitsoftware
|
reader phantompdf
|
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25608. User interaction is required to exploit this vulnerability in that the t…
|
CWE-416
Use After Free
|
CVE-2020-8856
|
2024-11-21 14:39 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|