|
210801
|
4.8 |
MEDIUM
Network
|
solarwinds
|
serv-u_ftp_server serv-u_mft_server
|
SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22428
|
2024-11-21 14:13 |
2021-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210802
|
9.8 |
CRITICAL
Network
|
guojusoft
|
jeecg
|
Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file to the component "jeecgFormDemoController.do?common…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-23083
|
2024-11-21 14:13 |
2021-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210803
|
6.1 |
MEDIUM
Network
|
opnsense
|
opnsense
|
An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not filtered and can redirect user to any website.
|
CWE-601
Open Redirect
|
CVE-2020-23015
|
2024-11-21 14:13 |
2021-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210804
|
6.1 |
MEDIUM
Network
|
fecmall_project
|
fecmall
|
An issue was found in yii2_fecshop 2.x. There is a reflected XSS vulnerability in the check cart page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22808
|
2024-11-21 14:13 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210805
|
9.8 |
CRITICAL
Network
|
vtiger
|
vtiger_crm
|
An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.
|
CWE-89
SQL Injection
|
CVE-2020-22807
|
2024-11-21 14:13 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210806
|
7.5 |
HIGH
Network
|
inim
|
smartliving_505_firmware smartliving_515_firmware smartliving_1050_firmware smartliving_1050g3_firmware smartliving_10100l_firmware smartliving_10100lg3_firmware
|
An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI <=6.x within the GetImage functionality. The application parses user supplied …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-22002
|
2024-11-21 14:13 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210807
|
5.4 |
MEDIUM
Network
|
safe
|
fme_server
|
Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitrary web script or HTML via modifying the name of the users. The XSS i…
|
CWE-79
Cross-site Scripting
|
CVE-2020-22790
|
2024-11-21 14:13 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210808
|
6.1 |
MEDIUM
Network
|
safe
|
fme_server
|
Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via the login page. The XSS is exe…
|
CWE-79
Cross-site Scripting
|
CVE-2020-22789
|
2024-11-21 14:13 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210809
|
7.5 |
HIGH
Network
|
etherpad
|
etherpad
|
Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with empty data would flatten all pads due to lack of ra…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-22785
|
2024-11-21 14:13 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210810
|
7.5 |
HIGH
Network
|
etherpad
|
ueberdb
|
In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could allow bypassing acce…
|
CWE-697
Incorrect Comparison
|
CVE-2020-22784
|
2024-11-21 14:13 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|