|
210631
|
6.1 |
MEDIUM
Network
|
rosariosis
|
rosariosis
|
RosarioSIS through 6.8-beta allows modules/Custom/NotifyParents.php XSS because of the href attributes for AddStudents.php and User.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15721
|
2024-11-21 14:06 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210632
|
6.8 |
MEDIUM
Network
|
dogtagpki
|
dogtagpki
|
In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. Since the verify parameter was hard-coded in all request functions, it was not …
|
CWE-295
Improper Certificate Validation
|
CVE-2020-15720
|
2024-11-21 14:06 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210633
|
4.2 |
MEDIUM
Network
|
openldap redhat opensuse mcafee oracle
|
openldap enterprise_linux leap policy_auditor blockchain_platform
|
libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subject…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-15719
|
2024-11-21 14:06 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210634
|
8.8 |
HIGH
Network
|
misp
|
misp
|
In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.
|
CWE-352
Origin Validation Error
|
CVE-2020-15711
|
2024-11-21 14:06 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210635
|
7.5 |
HIGH
Network
|
embedthis
|
appweb
|
Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This may result in a NULL pointer dereference and caus…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-15689
|
2024-11-21 14:06 |
2020-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210636
|
9.8 |
CRITICAL
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-15347
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210637
|
5.3 |
MEDIUM
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a /live/GLOBALS API with the CLOUDCNM key.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-15346
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210638
|
5.3 |
MEDIUM
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_instances_for_update API.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-15345
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210639
|
5.3 |
MEDIUM
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_user_id_and_key API.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-15344
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210640
|
5.3 |
MEDIUM
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-15343
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|