• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2020-5729
2020-04-23
N/A
6.1 MEDIUM
In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which can result in XSS. Any page that is able to trigger a UI Framework Error is susceptible to this issue.
CVE-2020-5728
2021-07-21
N/A
6.1 MEDIUM
OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (such as login.htm). There is insufficient validation for this parameter, which allows for the possibility of cross-site scripting.
CVE-2020-5727
2020-05-07
N/A
4.6 MEDIUM
Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated attacker to pair a rogue keypad to an armed system.
CVE-2020-5726
Grandstream, Ucm6204 Firmware
Gac2500_firmware, Gac2500, Gvc3202_firmware, Gvc3202, Gxv3275_firmware, Gxv3275, Gxv3240_firmware, Gxv3240, Gxp2200_firmware, Gxp2200
2020-03-31
N/A
7.5 HIGH
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover user passwords.
CVE-2020-5725
Grandstream, Ucm6204 Firmware
Gac2500_firmware, Gac2500, Gvc3202_firmware, Gvc3202, Gxv3275_firmware, Gxv3275, Gxv3240_firmware, Gxv3240, Gxp2200_firmware, Gxp2200
2020-03-31
N/A
5.9 MEDIUM
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the login action with a crafted username and, through the use of timing attacks, can discover user passwords.
CVE-2020-5724
Grandstream, Ucm6204 Firmware
Gac2500_firmware, Gac2500, Gvc3202_firmware, Gvc3202, Gxv3275_firmware, Gxv3275, Gxv3240_firmware, Gxv3240, Gxp2200_firmware, Gxp2200
2020-03-30
N/A
7.5 HIGH
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover user passwords.
CVE-2020-5723
Grandstream, Ucm6204 Firmware
Gac2500_firmware, Gac2500, Gvc3202_firmware, Gvc3202, Gxv3275_firmware, Gxv3275, Gxv3240_firmware, Gxv3240, Gxp2200_firmware, Gxp2200
2020-04-01
N/A
9.8 CRITICAL
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.
CVE-2020-5722
2022-02-10
N/A
9.8 CRITICAL
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.
CVE-2020-5721
2020-04-28
N/A
5.5 MEDIUM
MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file when the Keep Password field is set and no Master Password is set. Keep Password is set by default and, by default Master Password is not set. An attacker with access to the configuration file can extract a username and password to gain access to the router.
CVE-2020-5720
2020-02-10
N/A
5.9 MEDIUM
MikroTik WinBox before 3.21 is vulnerable to a path traversal vulnerability that allows creation of arbitrary files wherevere WinBox has write permissions. WinBox is vulnerable to this attack if it connects to a malicious endpoint or if an attacker mounts a man in the middle attack.
« Previous 1 … 3,412 3,413 3,414 3,415 3,416 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE