|
208851
|
4.3 |
MEDIUM
Network
|
optilinknetwork
|
op-xt71000n_firmware
|
A vulnerability found in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) att…
|
CWE-352
Origin Validation Error
|
CVE-2020-23586
|
2024-11-21 14:13 |
2022-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208852
|
9.8 |
CRITICAL
Network
|
optilinknetwork
|
op-xt71000n_firmware
|
Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tra…
|
CWE-77
Command Injection
|
CVE-2020-23584
|
2024-11-21 14:13 |
2022-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208853
|
6.5 |
MEDIUM
Network
|
optilinknetwork
|
op-xt71000n_firmware
|
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2, Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross site request forgery (CSRF) attack to …
|
CWE-352
Origin Validation Error
|
CVE-2020-23593
|
2024-11-21 14:13 |
2022-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208854
|
8.8 |
HIGH
Network
|
optilinknetwork
|
op-xt71000n_firmware
|
A remote attacker can conduct a cross-site request forgery (CSRF) attack on OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028. The vulnerability is due to insufficient …
|
CWE-352
Origin Validation Error
|
CVE-2020-23585
|
2024-11-21 14:13 |
2022-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208855
|
9.8 |
CRITICAL
Network
|
optilinknetwork
|
op-xt71000n_firmware
|
OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EX…
|
CWE-77
Command Injection
|
CVE-2020-23583
|
2024-11-21 14:13 |
2022-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208856
|
9.8 |
CRITICAL
Network
|
mkcms_project
|
mkcms
|
MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.
|
CWE-89
SQL Injection
|
CVE-2020-22819
|
2024-11-21 14:13 |
2022-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208857
|
9.8 |
CRITICAL
Network
|
mkcms_project
|
mkcms
|
MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter.
|
CWE-89
SQL Injection
|
CVE-2020-22818
|
2024-11-21 14:13 |
2022-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208858
|
7.5 |
HIGH
Network
|
asus
|
rt-n12e_firmware
|
Asus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / start_apply.htm, an attacker can change the administrator password without any authentication.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-23648
|
2024-11-21 14:13 |
2022-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208859
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview
|
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000001bcab.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-23560
|
2024-11-21 14:13 |
2022-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208860
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview
|
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000007d7f.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-23559
|
2024-11-21 14:13 |
2022-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|