Latest CVE Feed
-
5.4
MEDIUMCVE-2020-8825
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.... Read more
Affected Products : vanilla- Published: Feb. 10, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8824
Hitron CODA-4582U 7.1.1.30 devices allow XSS via a Managed Device name on the Wireless > Access Control > Add Managed Device screen.... Read more
- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2020-8823
htmlfile in lib/transport/htmlfile.js in SockJS before 0.3.0 is vulnerable to Reflected XSS via the /htmlfile c (aka callback) parameter.... Read more
Affected Products : sockjs- Published: Feb. 10, 2020
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2020-8822
Digi TransPort WR21 5.2.2.3, WR44 5.1.6.4, and WR44v2 5.1.6.9 devices allow stored XSS in the web application.... Read more
- Published: Feb. 10, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8821
An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint. A user may enter HTML code into the Command field and submit it. Then, after visiting the Action Logs Menu and displaying logs, the HTML cod... Read more
Affected Products : webmin- Published: Oct. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8820
An XSS Vulnerability exists in Webmin 1.941 and earlier affecting the Cluster Shell Commands Endpoint. A user may enter any XSS Payload into the Command field and execute it. Then, after revisiting the Cluster Shell Commands Menu, the XSS Payload will be ... Read more
Affected Products : webmin- Published: Oct. 12, 2020
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2020-8819
An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in the IPN callback processing function in cardgate/cardgate.php allows an attacker to remotely replace critical plugin settings (merchan... Read more
Affected Products : cardgate_payments- Published: Feb. 25, 2020
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2020-8818
An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in the IPN callback processing function in Controller/Payment/Callback.php allows an attacker to remotely replace critical plugin settings ... Read more
- Published: Feb. 25, 2020
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2020-8817
Dataiku DSS before 6.0.5 allows attackers write access to the project to modify the "Created by" metadata.... Read more
Affected Products : data_science_studio- Published: Sep. 14, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-8815
Improper connection handling in the base connection handler in IKTeam BearFTP before v0.3.1 allows a remote attacker to achieve denial of service via a Slowloris approach by sending a large volume of small packets.... Read more
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-8813
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.... Read more
Affected Products : fedora debian_linux cacti open-audit suse_package_hub suse_linux_enterprise_server- Published: Feb. 22, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8812
Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor. NOTE: the vendor's perspective is that this is "not a bug.... Read more
Affected Products : bludit- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-8811
ajax/profile-picture-upload.php in Bludit 3.10.0 allows authenticated users to change other users' profile pictures.... Read more
Affected Products : bludit- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2020-8810
An issue was discovered in Gurux GXDLMS Director through 8.5.1905.1301. When downloading OBIS codes, it does not verify that the downloaded files are actual OBIS codes and doesn't check for path traversal. This allows the attacker exploiting CVE-2020-8809... Read more
Affected Products : device_language_message_specification_director- Published: Feb. 25, 2020
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2020-8809
Gurux GXDLMS Director prior to 8.5.1905.1301 downloads updates to add-ins and OBIS code over an unencrypted HTTP connection. A man-in-the-middle attacker can prompt the user to download updates by modifying the contents of gurux.fi/obis/files.xml and guru... Read more
Affected Products : device_language_message_specification_director- Published: Feb. 25, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-8808
The CorsairLLAccess64.sys and CorsairLLAccess32.sys drivers in CORSAIR iCUE before 3.25.60 allow local non-privileged users (including low-integrity level processes) to read and write to arbitrary physical memory locations, and consequently gain NT AUTHOR... Read more
Affected Products : icue- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2020-8807
In Electric Coin Company Zcashd before 2.1.1-1, the time offset between messages could be leveraged to obtain sensitive information about the relationship between a suspected victim's address and an IP address, aka a timing side channel.... Read more
Affected Products : zcashd- Published: Feb. 05, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-8806
Electric Coin Company Zcashd before 2.1.1-1 allows attackers to trigger consensus failure and double spending. A valid chain could be incorrectly rejected because timestamp requirements on block headers were not properly enforced.... Read more
Affected Products : zcashd- Published: Feb. 05, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2020-8804
SuiteCRM through 7.11.10 allows SQL Injection via the SOAP API, the EmailUIAjax interface, or the MailMerge module.... Read more
Affected Products : suitecrm- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8803
SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list.... Read more
Affected Products : suitecrm- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024