|
209191
|
9.8 |
CRITICAL
Network
|
vr_cam
|
p1_firmware
|
VR CAM P1 Model P1 v1 has an incorrect access control vulnerability where an attacker can obtain complete access of the device from web (remote) without authentication.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-23512
|
2024-11-21 14:13 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209192
|
8.8 |
HIGH
Network
|
spiceworks
|
spiceworks
|
Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function.
|
CWE-352
Origin Validation Error
|
CVE-2020-23451
|
2024-11-21 14:13 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209193
|
6.1 |
MEDIUM
Network
|
mediakind
|
rx8200_firmware
|
MediaKind (formerly Ericsson) RX8200 5.13.3 devices are vulnerable to multiple reflected and stored XSS. An attacker has to inject JavaScript code directly in the "path" or "Services+ID" parameters a…
|
CWE-79
Cross-site Scripting
|
CVE-2020-22158
|
2024-11-21 14:13 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209194
|
5.4 |
MEDIUM
Network
|
spiceworks
|
spiceworks
|
Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on http://127.0.0.1/inventory/groups/ without output sanitiz…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23450
|
2024-11-21 14:13 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209195
|
5.4 |
MEDIUM
Network
|
laborator
|
neon
|
Laborator Neon dashboard v3 is affected by stored Cross Site Scripting (XSS) via the chat tab.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23576
|
2024-11-21 14:13 |
2020-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209196
|
5.4 |
MEDIUM
Network
|
webtareas_project
|
webtareas
|
webTareas v2.1 is affected by Cross Site Scripting (XSS) on "Search."
|
CWE-79
Cross-site Scripting
|
CVE-2020-23660
|
2024-11-21 14:13 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209197
|
5.4 |
MEDIUM
Network
|
webport
|
web_port
|
WebPort-v1.19.17121 is affected by Cross Site Scripting (XSS) on the "connections" feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23659
|
2024-11-21 14:13 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209198
|
5.4 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
PHP-Fusion 9.03.60 is affected by Cross Site Scripting (XSS) via infusions/member_poll_panel/poll_admin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23658
|
2024-11-21 14:13 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209199
|
5.4 |
MEDIUM
Network
|
naviwebs
|
navigatecms
|
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Configuration."
|
CWE-79
Cross-site Scripting
|
CVE-2020-23657
|
2024-11-21 14:13 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209200
|
5.4 |
MEDIUM
Network
|
naviwebs
|
navigatecms
|
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Content."
|
CWE-79
Cross-site Scripting
|
CVE-2020-23656
|
2024-11-21 14:13 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|