Export limit exceeded: 349256 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 45768 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (45768 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2020-11749 | 1 Pandorafms | 1 Pandora Fms | 2024-11-21 | 9.0 Critical |
| Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (XSS), which can run arbitrary code to allow Remote Code Execution as root or apache2. | ||||
| CVE-2020-11737 | 1 Zimbra | 1 Zimbra | 2024-11-21 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-Mail message or calendar invite to execute arbitrary JavaScript. The attack requires an A element containing an href attribute with a "www" substring (including the quotes) followed immediately by a DOM event listener such as onmouseover. This is fixed in 9.0.0 Patch 2. | ||||
| CVE-2020-11734 | 1 Cybersolutions | 1 Cybermail | 2024-11-21 | 6.1 Medium |
| cgi-bin/go in CyberSolutions CyberMail 5 or later allows XSS via the ACTION parameter. | ||||
| CVE-2020-11731 | 1 Davidlingren | 1 Media Library Assistant | 2024-11-21 | 6.1 Medium |
| The Media Library Assistant plugin before 2.82 for Wordpress suffers from multiple XSS vulnerabilities in all Settings/Media Library Assistant tabs, which allow remote authenticated users to execute arbitrary JavaScript. | ||||
| CVE-2020-11727 | 1 Algolplus | 1 Advanced Order Export For Woocommerce | 2024-11-21 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in the AlgolPlus Advanced Order Export For WooCommerce plugin 3.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the view/settings-form.php woe_post_type parameter. | ||||
| CVE-2020-11723 | 1 Cellebrite | 2 Ufed, Ufed Firmware | 2024-11-21 | 5.5 Medium |
| Cellebrite UFED 5.0 through 7.29 uses four hardcoded RSA private keys to authenticate to the ADB daemon on target devices. Extracted keys can be used to place evidence onto target devices when performing a forensic extraction. | ||||
| CVE-2020-11720 | 1 Bilanc | 1 Bilanc | 2024-11-21 | 9.8 Critical |
| An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. During the installation, it sets up administrative access by default with the account admin and password 0000. After the installation, users/admins are not prompted to change this password. | ||||
| CVE-2020-11719 | 1 Bilanc | 1 Bilanc | 2024-11-21 | 7.5 High |
| An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. It relies on broken encryption with a weak and guessable static encryption key. | ||||
| CVE-2020-11714 | 1 Etentech | 2 Psg-6528vm, Psg-6528vm Firmware | 2024-11-21 | 5.4 Medium |
| eten PSG-6528VM 1.1 devices allow XSS via System Contact or System Location. | ||||
| CVE-2020-11712 | 1 Open Upload Project | 1 Open Upload | 2024-11-21 | 6.1 Medium |
| Open Upload through 0.4.3 allows XSS via index.php?action=u and the filename field. | ||||
| CVE-2020-11711 | 1 Stormshield | 1 Stormshield Network Security | 2024-11-21 | 4.8 Medium |
| An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded from the admin panel. The resulting file is rendered on the authentication interface of the admin panel. It is possible to inject malicious HTML content in order to execute JavaScript inside a victim's browser. This results in a stored XSS on the authentication interface of the admin panel. Moreover, an unsecured authentication form is present on the authentication interface of the SSL VPN captive portal. Users are allowed to save their credentials inside the browser. If an administrator saves his credentials through this unsecured form, these credentials could be stolen via the stored XSS on the admin panel without user interaction. Another possible exploitation would be modification of the authentication form of the admin panel into a malicious form. | ||||
| CVE-2020-11704 | 1 Provideserver | 1 Provide Ftp Server | 2024-11-21 | 6.1 Medium |
| An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Web Interface has Multiple Stored and Reflected XSS. GetInheritedProperties is Reflected via the groups parameter. GetUserInfo is Reflected via POST data. SetUserInfo is Stored via the general parameter. | ||||
| CVE-2020-11702 | 1 Provideserver | 1 Provide Ftp Server | 2024-11-21 | 6.1 Medium |
| An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The User Web Interface has Multiple Stored and Reflected XSS issues. Collaborate is Reflected via the filename parameter. Collaborate is Stored via the displayname parameter. Deletemultiple is Reflected via the files parameter. Share is Reflected via the target parameter. Share is Stored via the displayname parameter. Waitedit is Reflected via the Host header. | ||||
| CVE-2020-11697 | 1 Combodo | 1 Itop | 2024-11-21 | 6.1 Medium |
| In Combodo iTop, dashboard ids can be exploited with a reflective XSS payload. This is fixed in all iTop packages (community, essential, professional) for version 2.7.0 and in iTop essential and iTop professional packages for version 2.6.4. | ||||
| CVE-2020-11696 | 1 Combodo | 1 Itop | 2024-11-21 | 6.1 Medium |
| In Combodo iTop a menu shortcut name can be exploited with a stored XSS payload. This is fixed in all iTop packages (community, essential, professional) in version 2.7.0 and iTop essential and iTop professional in version 2.6.4. | ||||
| CVE-2020-11626 | 1 Primekey | 1 Ejbca | 2024-11-21 | 6.1 Medium |
| An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. Two Cross Side Scripting (XSS) vulnerabilities have been found in the Public Web and the Certificate/CRL download servlets. | ||||
| CVE-2020-11615 | 2 Intel, Nvidia | 2 Bmc Firmware, Dgx-1 | 2024-11-21 | 7.5 High |
| NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which it uses a hard-coded RC4 cipher key, which may lead to information disclosure. | ||||
| CVE-2020-11584 | 2 Linux, Plesk | 2 Linux Kernel, Onyx | 2024-11-21 | 6.1 Medium |
| A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter. | ||||
| CVE-2020-11583 | 2 Microsoft, Plesk | 2 Windows, Obsidian | 2024-11-21 | 6.1 Medium |
| A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter. | ||||
| CVE-2020-11556 | 1 Castlerock | 1 Snmpc Online | 2024-11-21 | 5.4 Medium |
| An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There are multiple persistent (stored) and reflected XSS vulnerabilities. | ||||