|
209511
|
8.8 |
HIGH
Network
|
sagemcom
|
f\@st_5280_router_firmware
|
Sagemcom F@ST 5280 routers using firmware version 1.150.61 have insecure deserialization that allows any authenticated user to perform a privilege escalation to any other user. By making a request wi…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-24034
|
2024-11-21 14:14 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209512
|
8.8 |
HIGH
Network
|
oswapp
|
warehouse_inventory_system
|
A Cross-Site Request Forgery (CSRF) vulnerability in edit_user.php in OSWAPP Warehouse Inventory System (aka OSWA-INV) through 2020-08-10 allows remote attackers to change the admin's password after …
|
CWE-352
Origin Validation Error
|
CVE-2020-23836
|
2024-11-21 14:14 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209513
|
6.1 |
MEDIUM
Network
|
tailor_management_system_project
|
tailor_management_system
|
A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Management System v1.0 allows remote attackers to harvest keys pressed by an unauth…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23835
|
2024-11-21 14:14 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209514
|
6.1 |
MEDIUM
Network
|
stock_management_system_project
|
stock_management_system
|
A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Stock Management System v1.0 allows remote attackers to harvest login credentials and sess…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23831
|
2024-11-21 14:14 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209515
|
8.8 |
HIGH
Network
|
librehealth
|
librehealth_ehr
|
interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the host…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-23829
|
2024-11-21 14:14 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209516
|
7.5 |
HIGH
Network
|
gmapfp
|
gmapfp
|
gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload function without authenticating to the application and also can upload files due the…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-23971
|
2024-11-21 14:14 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209517
|
7.5 |
HIGH
Network
|
liferay
|
liferay_portal
|
The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is recorded, which allows remote attackers to perform a denial of service attack by …
|
CWE-601
Open Redirect
|
CVE-2020-24554
|
2024-11-21 14:14 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209518
|
8.8 |
HIGH
Network
|
zyxel
|
vmg5313-b30b_firmware
|
Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by shell injection.
|
CWE-78
OS Command
|
CVE-2020-24354
|
2024-11-21 14:14 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209519
|
8.8 |
HIGH
Adjacent
|
tp-link
|
tl-wa855re_firmware
|
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtai…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-24363
|
2024-11-21 14:14 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209520
|
9.8 |
CRITICAL
Network
|
online_book_store_project
|
online_book_store
|
In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-24115
|
2024-11-21 14:14 |
2020-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|