• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2020-10250
Direx-pro Firmware, Meinbwa
Direx-pro_firmware, Direx-pro
2020-03-10
N/A
9.8 CRITICAL
BWA DiREX-Pro 1.2181 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the PKG parameter to uninstall.php3.
CVE-2020-1025
2021-07-21
N/A
9.8 CRITICAL
An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation, aka 'Microsoft Office Elevation of Privilege Vulnerability'.
CVE-2020-10249
Direx-pro Firmware, Meinbwa
Direx-pro_firmware, Direx-pro
2021-07-21
N/A
5.3 MEDIUM
BWA DiREX-Pro 1.2181 devices allow full path disclosure via an invalid name array parameter to val_soft.php3.
CVE-2020-10248
Direx-pro Firmware, Meinbwa
Direx-pro_firmware, Direx-pro
2021-07-21
N/A
7.5 HIGH
BWA DiREX-Pro 1.2181 devices allow remote attackers to discover passwords via a direct request to val_users.php3.
CVE-2020-10247
2020-04-02
N/A
6.1 MEDIUM
MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is related to app/View/Elements/Events/View/sighting_field.ctp.
CVE-2020-10246
2020-04-02
N/A
6.1 MEDIUM
MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is related to app/View/Users/statistics_orgs.ctp.
CVE-2020-10245
2020-04-01
N/A
9.8 CRITICAL
CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.
CVE-2020-10244
2020-03-10
N/A
7.5 HIGH
JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.
CVE-2020-10243
2020-03-18
N/A
9.8 CRITICAL
An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Featured Articles frontend menutype.
CVE-2020-10242
2020-03-18
N/A
6.1 MEDIUM
An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaScript allows XSS attacks.
« Previous 1 … 4,924 4,925 4,926 4,927 4,928 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE