|
209281
|
8.8 |
HIGH
Network
|
smartstore
|
smartstorenet
|
An issue was discovered in SmartStoreNET before 4.0.1. It does not properly consider the need for a CustomModelPartAttribute decoration in certain ModelBase.CustomProperties situations.
|
NVD-CWE-noinfo
|
CVE-2020-27996
|
2024-11-21 14:22 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209282
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_applications_manager
|
SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter.
|
CWE-89
SQL Injection
|
CVE-2020-27995
|
2024-11-21 14:22 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209283
|
5.3 |
MEDIUM
Network
|
hrsale
|
hrsale
|
Hrsale 2.0.0 allows download?type=files&filename=../ directory traversal to read arbitrary files.
|
CWE-22
Path Traversal
|
CVE-2020-27993
|
2024-11-21 14:22 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209284
|
7.5 |
HIGH
Network
|
sonarsource
|
sonarqube
|
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it …
|
CWE-306 CWE-312
Missing Authentication for Critical Function Cleartext Storage of Sensitive Information
|
CVE-2020-27986
|
2024-11-21 14:22 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209285
|
5.4 |
MEDIUM
Network
|
genexis
|
platinum-4410_firmware
|
Genexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to perform malicious actions in which the XSS popup will affect all privileged us…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27980
|
2024-11-21 14:22 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209286
|
7.5 |
HIGH
Network
|
shibboleth
|
identity_provider
|
Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause a login flow to trigger Java heap exhaustion due to the creation of objects in …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-27978
|
2024-11-21 14:22 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209287
|
9.8 |
CRITICAL
Network
|
oscommerce
|
oscommerce
|
osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the application. This affects the PHP mail function, and the s…
|
CWE-78
OS Command
|
CVE-2020-27976
|
2024-11-21 14:22 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209288
|
8.8 |
HIGH
Network
|
oscommerce
|
oscommerce
|
osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-27975
|
2024-11-21 14:22 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209289
|
6.1 |
MEDIUM
Network
|
quadient
|
mail_accounting
|
NeoPost Mail Accounting Software Pro 5.0.6 allows php/Commun/FUS_SCM_BlockStart.php?code= XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-27974
|
2024-11-21 14:22 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209290
|
5.4 |
MEDIUM
Network
|
mediawiki
|
mediawiki
|
The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certain varieties of games were created within MediaWiki, their names or titles coul…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27957
|
2024-11-21 14:22 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|