Search

Search Results (361555 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-15050 1 Supremainc 1 Biostar 2 2024-11-21 7.5 High
An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary files from the server via Directory Traversal.
CVE-2020-15049 3 Fedoraproject, Redhat, Squid-cache 3 Fedora, Enterprise Linux, Squid 2024-11-21 9.9 Critical
An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can succeed against the HTTP cache. The client sends an HTTP request with a Content-Length header containing "+\ "-" or an uncommon shell whitespace character prefix to the length field-value.
CVE-2020-15047 1 Trojita Project 1 Trojita 2024-11-21 5.9 Medium
MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to spoof SMTP servers.
CVE-2020-15046 1 Supermicro 3 X10drh-it, X10drh-it Bios, X10drh-it Firmware 2024-11-21 8.8 High
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed versions are BIOS 3.2 and firmware 03.88.
CVE-2020-15043 1 Iball 2 Wrb303n, Wrb303n Firmware 2024-11-21 6.5 Medium
iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP addresses.
CVE-2020-15041 1 Php-fusion 1 Php-fusion 2024-11-21 4.8 Medium
PHP-Fusion 9.03.60 allows XSS via the administration/site_links.php Add Site Link field.
CVE-2020-15038 1 Seedprod 1 Coming Soon Page\, Under Construction \& Maintenance Mode 2024-11-21 5.4 Medium
The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.
CVE-2020-15037 1 Nedi 1 Nedi 2024-11-21 5.4 Medium
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Reports-Devices.php page st[] parameter.
CVE-2020-15036 1 Nedi 1 Nedi 2024-11-21 5.4 Medium
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Linked.php dv parameter.
CVE-2020-15035 1 Nedi 1 Nedi 2024-11-21 5.4 Medium
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Monitoring-Map.php hde parameter.
CVE-2020-15034 1 Nedi 1 Nedi 2024-11-21 5.4 Medium
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Monitoring-Setup.php tet parameter.
CVE-2020-15033 1 Nedi 1 Nedi 2024-11-21 5.4 Medium
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the snmpget.php ip parameter.
CVE-2020-15032 1 Nedi 1 Nedi 2024-11-21 5.4 Medium
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Monitoring-Incidents.php id parameter.
CVE-2020-15031 1 Nedi 1 Nedi 2024-11-21 5.4 Medium
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Assets-Management.php chg parameter.
CVE-2020-15030 1 Nedi 1 Nedi 2024-11-21 5.4 Medium
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Routes.php rtr parameter.
CVE-2020-15029 1 Nedi 1 Nedi 2024-11-21 5.4 Medium
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Assets-Management.php sn parameter.
CVE-2020-15028 1 Nedi 1 Nedi 2024-11-21 5.4 Medium
NeDi 1.9C is vulnerable to a cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Map.php xo parameter.
CVE-2020-15027 1 Connectwise 1 Automate 2024-11-21 9.8 Critical
ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7 and in a hotfix for 2019.12.
CVE-2020-15026 1 Bludit 1 Bludit 2024-11-21 4.9 Medium
Bludit 3.12.0 allows admins to use a /plugin-backup-download?file=../ directory traversal approach for arbitrary file download via backup/plugin.php.
CVE-2020-15025 4 Netapp, Ntp, Opensuse and 1 more 27 8300, 8300 Firmware, 8700 and 24 more 2024-11-21 4.4 Medium
ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.