|
208661
|
9.8 |
CRITICAL
Network
|
nagios
|
fusion nagios_xi
|
Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to …
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-28900
|
2024-11-21 14:23 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208662
|
6.1 |
MEDIUM
Network
|
projectworlds
|
travel_management_system
|
XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via the name field
|
CWE-79
Cross-site Scripting
|
CVE-2020-29205
|
2024-11-21 14:23 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208663
|
5.4 |
MEDIUM
Network
|
deskpro
|
deskpro
|
Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to an account takeover via custom email templates.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28722
|
2024-11-21 14:23 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208664
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite 7.10.4 and earlier allows XSS via crafted content to reach an undocumented feature, such as 
|
CVE-2020-28943
|
2024-11-21 14:23 |
2021-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208667
|
7.5 |
HIGH
Network
|
abus
|
secvest_wireless_alarm_system_fuaa50000_firmware
|
The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can use this vulnerability to obtain sensitive inform…
|
CWE-287
Improper Authentication
|
CVE-2020-28973
|
2024-11-21 14:23 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208668
|
5.3 |
MEDIUM
Network
|
resourcexpress
|
resourcexpress
|
In QED ResourceXpress through 4.9k, a large numeric or alphanumeric value submitted in specific URL parameters causes a server error in script execution due to insufficient input validation.
|
CWE-20
Improper Input Validation
|
CVE-2020-28898
|
2024-11-21 14:23 |
2021-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208669
|
9.8 |
CRITICAL
Network
|
monitorr
|
monitorr
|
An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows an unauthorized person to create valid credentials.
|
CWE-863
Incorrect Authorization
|
CVE-2020-28872
|
2024-11-21 14:23 |
2021-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208670
|
8.8 |
HIGH
Adjacent
|
askey
|
rtf3505vw-n1_br_sv_g000_r3505vwn1001_s32_7_firmware
|
Askey Fiber Router RTF3505VW-N1 BR_SV_g000_R3505VWN1001_s32_7 devices allow Remote Code Execution and retrieval of admin credentials to log into the Dashboard or login via SSH, leading to code execut…
|
CWE-78
OS Command
|
CVE-2020-28695
|
2024-11-21 14:23 |
2021-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|