|
199491
|
9.8 |
CRITICAL
Network
|
zend
|
zendto
|
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attacker to gain administrative access with a large number of r…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2020-8986
|
2024-11-21 14:39 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199492
|
8.8 |
HIGH
Network
|
zend
|
zendto
|
ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2020-8985
|
2024-11-21 14:39 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199493
|
7.5 |
HIGH
Network
|
zend
|
zendto
|
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.
|
CWE-346
Origin Validation Error
|
CVE-2020-8984
|
2024-11-21 14:39 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199494
|
9.8 |
CRITICAL
Network
|
quest
|
foglight_evolve
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve 9.0.0. Authentication is not required to exploit this vulnerability. The specif…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-8868
|
2024-11-21 14:39 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199495
|
6.5 |
MEDIUM
Network
|
horde debian
|
groupware horde_form debian_linux
|
This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. The…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-8866
|
2024-11-21 14:39 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199496
|
6.3 |
MEDIUM
Network
|
horde debian
|
groupware debian_linux
|
This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. Th…
|
CWE-22
Path Traversal
|
CVE-2020-8865
|
2024-11-21 14:39 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199497
|
7.5 |
HIGH
Network
|
psi
|
electronic_logbook
|
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ELOG Electronic Logbook 3.1.4-283534d. Authentication is not required to exploit this v…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-8859
|
2024-11-21 14:39 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199498
|
8.8 |
HIGH
Adjacent
|
dlink
|
dir-878_firmware dir-882_firmware dir-867_firmware
|
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not re…
|
CWE-697
Incorrect Comparison
|
CVE-2020-8864
|
2024-11-21 14:39 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199499
|
8.8 |
HIGH
Adjacent
|
dlink
|
dir-878_firmware dir-882_firmware dir-867_firmware
|
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not re…
|
CWE-287
Improper Authentication
|
CVE-2020-8863
|
2024-11-21 14:39 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199500
|
5.5 |
MEDIUM
Local
|
parallels
|
parallels_desktop
|
This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute low-privileged code…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-8876
|
2024-11-21 14:39 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|