CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dlink
1Dsl Gs225 Firmware
Jun 17, 2026
Apr 10, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
D-Link DSL-GS225 J1 AU_1.0.4 devices allow an admin to execute OS commands by placing shell metacharacters after a supported CLI command, as demonstrated by ping -c1 127.0.0.1; cat/etc/passwd. The CLI is reachable by TEL...Show more
D-Link DSL-GS225 J1 AU_1.0.4 devices allow an admin to execute OS commands by placing shell metacharacters after a supported CLI command, as demonstrated by ping -c1 127.0.0.1; cat/etc/passwd. The CLI is reachable by TELNET.Show less
1Schmid Telecom
1Zi 620 V400 Firmware
Jun 17, 2026
Feb 6, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Schmid ZI 620 V400 VPN 090 routers allow an attacker to execute OS commands as root via shell metacharacters to an entry on the SSH subcommand menu, as demonstrated by ping.
1Rasilient
1Pixelstor 5000 Firmware
Jun 17, 2026
Jan 9, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in Option/optionsAll.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows remote attackers to inject arbitrary web script or HTML via the ContentFrame parame...Show more
A cross-site scripting (XSS) vulnerability in Option/optionsAll.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows remote attackers to inject arbitrary web script or HTML via the ContentFrame parameter.Show less
1Rasilient
1Pixelstor 5000 Firmware
Jun 17, 2026
Jan 9, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
contentHostProperties.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows authenticated attackers to remotely execute code via the name parameter.
1Rasilient
1Pixelstor 5000 Firmware
Jun 17, 2026
Jan 9, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the lang parameter.
1Dotcms
1Dotcms
Jun 17, 2026
Feb 5, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory)...Show more
dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g., .jsp files) into /webapps/ROOT/assets/tmp_upload, which can lead to remote command execution (with the permissions of the user running the dotCMS application).Show less
1Auth0
1Login By Auth0
Jun 17, 2026
Apr 1, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Login by Auth0 plugin before 4.0.0 for WordPress allows stored XSS on multiple pages, a different issue than CVE-2020-5392.
1Openmicroscopy
1Omero
Jun 17, 2026
Jun 17, 2020
N/A· v4
3.8 LOW· v3
5.5 MEDIUM· v2
In OMERO before 5.6.1, group owners can access members' data in other groups.
2Fedoraproject
Gnome
2Fedora
Glib
Jun 17, 2026
Jan 9, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is...Show more
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.Show less
1Eaton
19000x Programming And Configuration Software
Jun 17, 2026
Sep 30, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attacker to execute arbitrary code by replacing the required DLLs with malicious DLLs when the software t...Show more
A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attacker to execute arbitrary code by replacing the required DLLs with malicious DLLs when the software try to load vci11un6.DLL and cinpl.DLL.Show less
1Eaton
1Secureconnect
Jun 17, 2026
Aug 12, 2020
N/A· v4
3.9 LOW· v3
2.1 LOW· v2
Eaton's Secure connect mobile app v1.7.3 & prior stores the user login credentials in logcat file when user create or register the account on the Mobile app. A malicious app or unauthorized user can harvest the informati...Show more
Eaton's Secure connect mobile app v1.7.3 & prior stores the user login credentials in logcat file when user create or register the account on the Mobile app. A malicious app or unauthorized user can harvest the information and later on can use the information to monitor and control the user's account and associated devices.Show less
1Eaton
1Intelligent Power Manager
Jun 17, 2026
May 7, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system configuration files by sending specially crafted requests. This can result...Show more
Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system configuration files by sending specially crafted requests. This can result in non-admin users manipulating the system configurations via uploading the configurations with incorrect parameters.Show less
1Eaton
1Intelligent Power Manager
Jun 17, 2026
May 7, 2020
N/A· v4
7.3 HIGH· v3
6.0 MEDIUM· v2
Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via speciall...Show more
Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file in the application.Show less
1Eaton
1Ups Companion
Jun 17, 2026
Mar 23, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval” i...Show more
UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval” in “Update Manager” class when software attempts to see if there are updates available. This results in arbitrary code execution on the machine where software is installed.Show less
1Fortinet
2Fortios
Fortiproxy
Jun 17, 2026
Oct 21, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A cleartext storage of sensitive information vulnerability in FortiOS command line interface in versions 6.2.4 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an authenticated attacker to obtain sensitive i...Show more
A cleartext storage of sensitive information vulnerability in FortiOS command line interface in versions 6.2.4 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an authenticated attacker to obtain sensitive information such as users passwords by connecting to FortiGate CLI and executing the "diag sys ha checksum show" command.Show less
1Fortinet
1Fortiadc Firmware
Jun 17, 2026
Apr 7, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenticated attacker to perform a cross site scripting attack (XSS) via the name parameter.
1Fortinet
1Fortiweb
Jun 17, 2026
Mar 17, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An improper neutralization of input vulnerability in FortiWeb allows a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the Disclaimer Description of a Replacement Message.
1Fortinet
1Fortideceptor
Jun 17, 2026
Jun 22, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An insufficient session expiration vulnerability in FortiDeceptor 3.0.0 and below allows an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that sess...Show more
An insufficient session expiration vulnerability in FortiDeceptor 3.0.0 and below allows an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID via other, hypothetical attacks.Show less
1Fortinet
1Fortiisolator
Jun 17, 2026
Mar 12, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An improper neutralization of input vulnerability in the URL Description in Fortinet FortiIsolator version 1.2.2 allows a remote authenticated attacker to perform a cross site scripting attack (XSS).
1Fortinet
1Fortianalyzer
Jun 17, 2026
Jun 4, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the Description Area.
1Grin
1Grin
Jun 17, 2026
Jan 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Grin through 2.1.1 has Insufficient Validation.
1Os4ed
1Opensis
Jun 17, 2026
Aug 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.
1Prestashop
1Prestashop
Jun 17, 2026
Jan 9, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAccessesController.php, themes/default/template/header.tpl, and themes/new-theme/js/header.js.
1Gpac
1Gpac
Jun 17, 2026
Jan 9, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_m2ts_stream_process_pmt() in media_tools/m2ts_mux.c.
1Gpac
1Gpac
Jun 17, 2026
Jan 9, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_isom_get_media_data_size() in isomedia/isom_read.c.