|
209651
|
7.5 |
HIGH
Network
|
objectplanet
|
opinio
|
ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. This can be used to retrieve possibly sensitive serverInfo data.
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2020-26565
|
2024-11-21 14:20 |
2021-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209652
|
6.5 |
MEDIUM
Network
|
objectplanet
|
opinio
|
ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey template (containing a link to this .css file)…
|
CWE-611
XXE
|
CVE-2020-26564
|
2024-11-21 14:20 |
2021-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209653
|
6.1 |
MEDIUM
Network
|
objectplanet
|
opinio
|
ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored XSS if input to survey/admin/*.do is accepted from …
|
CWE-79
Cross-site Scripting
|
CVE-2020-26563
|
2024-11-21 14:20 |
2021-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209654
|
7.5 |
HIGH
Network
|
rocket.chat
|
rocket.chat
|
The Rocket.Chat desktop application 2.17.11 opens external links without user interaction.
|
NVD-CWE-noinfo
|
CVE-2020-26763
|
2024-11-21 14:20 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209655
|
5.4 |
MEDIUM
Network
|
tripplite
|
su2200rtxl2ua_firmware
|
A stored cross-site scripting (XSS) vulnerability was discovered in /Forms/device_vars_1 on TrippLite SU2200RTXL2Ua with firmware version 12.04.0055. This vulnerability allows authenticated attackers…
|
CWE-79
Cross-site Scripting
|
CVE-2020-26801
|
2024-11-21 14:20 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209656
|
6.1 |
MEDIUM
Network
|
2sic
|
2sxc
|
An issue was discovered in 2sic 2sxc before 11.22. A XSS vulnerability in the sxcver parameter of dnn/ui.html allows an attacker to craft a malicious URL that executes a JavaScript payload in a victi…
|
CWE-79
Cross-site Scripting
|
CVE-2020-26885
|
2024-11-21 14:20 |
2021-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209657
|
5.4 |
MEDIUM
Network
|
pfsense
|
pfsense
|
A stored cross-site scripting (XSS) vulnerability was discovered in pfSense 2.4.5-p1 which allows an authenticated attacker to execute arbitrary web scripts via exploitation of the load_balancer_moni…
|
CWE-79
Cross-site Scripting
|
CVE-2020-26693
|
2024-11-21 14:20 |
2021-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209658
|
8.8 |
HIGH
Network
|
bigtreecms
|
bigtree_cms
|
A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands through a crafted request sent to the server via the 'Create…
|
CWE-78
OS Command
|
CVE-2020-26670
|
2024-11-21 14:20 |
2021-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209659
|
5.4 |
MEDIUM
Network
|
bigtreecms
|
bigtree_cms
|
A stored cross-site scripting (XSS) vulnerability was discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary web scripts or HTML via the page content…
|
CWE-79
Cross-site Scripting
|
CVE-2020-26669
|
2024-11-21 14:20 |
2021-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209660
|
8.8 |
HIGH
Network
|
bigtreecms
|
bigtree_cms
|
A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to inject a malicious SQL query to the applications via…
|
CWE-89
SQL Injection
|
CVE-2020-26668
|
2024-11-21 14:20 |
2021-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|