|
210481
|
9.8 |
CRITICAL
Network
|
caret
|
caret
|
A specially crafted Markdown document could cause the execution of malicious JavaScript code in Caret Editor before 4.0.0-rc22.
|
NVD-CWE-noinfo
|
CVE-2020-20269
|
2024-11-21 14:11 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210482
|
6.5 |
MEDIUM
Adjacent
|
huawei
|
cloudengine_12800_firmware cloudengine_5800_firmware cloudengine_6800_firmware cloudengine_7800_firmware
|
There is an out-of-bounds read vulnerability in Huawei CloudEngine products. The software reads data past the end of the intended buffer when parsing certain PIM message, an adjacent attacker could s…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-1865
|
2024-11-21 14:11 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210483
|
6.5 |
MEDIUM
Adjacent
|
huawei
|
nip6800_firmware s12700_firmware s2700_firmware s5700_firmware s6700_firmware s7700_firmware s9700_firmware secospace_usg6600_firmware usg9500_firmware
|
There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when parsing certain crafted DHCP messages. Successful exploit could caus…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-1866
|
2024-11-21 14:11 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210484
|
5.5 |
MEDIUM
Local
|
huawei
|
jackman-al00d_firmware
|
There is a resource management error vulnerability in Jackman-AL00D versions 8.2.0.185(C00R2P1). Local attackers construct malicious application files, causing system applications to run abnormally.
|
NVD-CWE-noinfo
|
CVE-2020-1848
|
2024-11-21 14:11 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210485
|
5.4 |
MEDIUM
Network
|
zzcms
|
zzcms
|
There is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via user/login.php
|
CWE-79
Cross-site Scripting
|
CVE-2020-20285
|
2024-11-21 14:11 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210486
|
9.8 |
CRITICAL
Network
|
troglobit
|
uftpd
|
There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server versions 2.7 to 2.10 due to improper implementation of a chroot jail in common.c's…
|
CWE-22
Path Traversal
|
CVE-2020-20277
|
2024-11-21 14:11 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210487
|
9.8 |
CRITICAL
Network
|
troglobit
|
uftpd
|
An unauthenticated stack-based buffer overflow vulnerability in common.c's handle_PORT in uftpd FTP server versions 2.10 and earlier can be abused to cause a crash and could potentially lead to remot…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-20276
|
2024-11-21 14:11 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210488
|
6.1 |
MEDIUM
Network
|
flexmonster
|
pivot_table_\&_charts
|
Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table & Charts 2.7.17.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20142
|
2024-11-21 14:11 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210489
|
6.1 |
MEDIUM
Network
|
flexmonster
|
pivot_table_\&_charts
|
Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20141
|
2024-11-21 14:11 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210490
|
6.1 |
MEDIUM
Network
|
flexmonster
|
pivot_table_\&_charts
|
Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20140
|
2024-11-21 14:11 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|