|
208541
|
7.5 |
HIGH
Network
|
qsc
|
q-sys_core_manager
|
An issue was discovered in QSC Q-SYS Core Manager 8.2.1. By utilizing the TFTP service running on UDP port 69, a remote attacker can perform a directory traversal and obtain operating system files vi…
|
CWE-22
Path Traversal
|
CVE-2020-24990
|
2024-11-21 14:16 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208542
|
6.5 |
MEDIUM
Network
|
fireeye
|
email_malware_protection_system
|
eMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort, sort_by, search{URL], or search[attachment] parameter to the email sear…
|
CWE-89
SQL Injection
|
CVE-2020-25034
|
2024-11-21 14:16 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208543
|
7.8 |
HIGH
Local
|
fruitywifi_project
|
fruitywifi
|
FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform a system-level (root) local privilege escalation, allowing an attacker to gain …
|
CWE-287 CWE-269
Improper Authentication Improper Privilege Management
|
CVE-2020-24848
|
2024-11-21 14:16 |
2020-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208544
|
4.3 |
MEDIUM
Network
|
fruitywifi_project
|
fruitywifi
|
A Cross-Site Request Forgery (CSRF) vulnerability is identified in FruityWifi through 2.4. Due to a lack of CSRF protection in page_config_adv.php, an unauthenticated attacker can lure the victim to …
|
CWE-352
Origin Validation Error
|
CVE-2020-24847
|
2024-11-21 14:16 |
2020-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208545
|
7.5 |
HIGH
Network
|
mind
|
imind_server
|
InterMind iMind Server through 3.13.65 allows remote unauthenticated attackers to read the self-diagnostic archive via a direct api/rs/monitoring/rs/api/system/dump-diagnostic-info?server=127.0.0.1 r…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2020-24765
|
2024-11-21 14:16 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208546
|
7.8 |
HIGH
Local
|
socket.io-file_project
|
socket.io-file
|
The socket.io-file package through 2.0.31 for Node.js relies on client-side validation of file types, which allows remote attackers to execute arbitrary code by uploading an executable file via a mod…
|
CWE-20
Improper Input Validation
|
CVE-2020-24807
|
2024-11-21 14:16 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208547
|
7.5 |
HIGH
Network
|
envoyproxy
|
envoy
|
Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization.
|
NVD-CWE-noinfo
|
CVE-2020-25018
|
2024-11-21 14:16 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208548
|
8.3 |
HIGH
Network
|
envoyproxy
|
envoy
|
Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy’s setCopy() header map API does not replace all existing occurences of a non-i…
|
NVD-CWE-Other
|
CVE-2020-25017
|
2024-11-21 14:16 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208549
|
5.4 |
MEDIUM
Network
|
get-simple
|
getsimple_cms
|
GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page
|
CWE-79
Cross-site Scripting
|
CVE-2020-24861
|
2024-11-21 14:16 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208550
|
5.4 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every …
|
CWE-79
Cross-site Scripting
|
CVE-2020-24860
|
2024-11-21 14:16 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|