|
209181
|
8.8 |
HIGH
Network
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-22278
|
2024-11-21 14:13 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209182
|
8.0 |
HIGH
Network
|
codection
|
import_and_export_users_and_customers
|
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-22277
|
2024-11-21 14:13 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209183
|
9.8 |
CRITICAL
Network
|
weformspro
|
weforms
|
WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-22276
|
2024-11-21 14:13 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209184
|
8.8 |
HIGH
Network
|
easyregistrationforms
|
easy_registration_forms
|
Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the fo…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-22275
|
2024-11-21 14:13 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209185
|
9.8 |
CRITICAL
Network
|
moxa
|
vport_461_firmware
|
A command injection vulnerability exists in Moxa Inc VPort 461 Series Firmware Version 3.4 or lower that could allow a remote attacker to execute arbitrary commands in Moxa's VPort 461 Series Industr…
|
CWE-77
Command Injection
|
CVE-2020-23639
|
2024-11-21 14:13 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209186
|
7.5 |
HIGH
Network
|
snap7_project
|
snap7
|
The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to No and S7 writes a var function, the Snap7 server will be crashe…
|
NVD-CWE-noinfo
|
CVE-2020-22552
|
2024-11-21 14:13 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209187
|
5.4 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterface.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22842
|
2024-11-21 14:13 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209188
|
6.1 |
MEDIUM
Network
|
hack
|
hfish
|
An issue was discovered in HFish 0.5.1. When a payload is inserted where the password is entered, XSS code is triggered when the administrator views the information.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22481
|
2024-11-21 14:13 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209189
|
6.1 |
MEDIUM
Network
|
untis
|
webuntis
|
Untis WebUntis before 2020.9.6 allows XSS in multiple functions that store information.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22453
|
2024-11-21 14:13 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209190
|
5.3 |
MEDIUM
Network
|
verint
|
workforce_optimization
|
Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-23446
|
2024-11-21 14:13 |
2020-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|