|
199111
|
7.5 |
HIGH
Network
|
arubanetworks
|
cx_6200f_firmware cx_6300_firmware cx_6400_firmware cx_8320_firmware cx_8325_firmware cx_8400_firmware
|
Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local D…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7121
|
2024-11-21 14:36 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199112
|
7.4 |
HIGH
Network
|
bosch
|
smart_home
|
Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17.1 potentially allows to intercept video contents by performing a man-in-the-mi…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-6781
|
2024-11-21 14:36 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199113
|
4.3 |
MEDIUM
Network
|
mcafee
|
email_gateway
|
Path Traversal vulnerability in McAfee McAfee Email Gateway (MEG) prior to 7.6.406 allows remote attackers to traverse the file system to access files or directories that are outside of the restricte…
|
CWE-22
Path Traversal
|
CVE-2020-7268
|
2024-11-21 14:36 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199114
|
3.6 |
LOW
Local
|
php debian tenable
|
php debian_linux tenable.sc
|
In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which …
|
CWE-416
Use After Free
|
CVE-2020-7068
|
2024-11-21 14:36 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199115
|
4.9 |
MEDIUM
Network
|
arubanetworks
|
analytics_and_location_engine
|
A vulnerability exists in the Aruba Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier firmware that allows an already authenticated administrative user to arbitrarily m…
|
NVD-CWE-noinfo
|
CVE-2020-7119
|
2024-11-21 14:36 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199116
|
9.1 |
CRITICAL
Network
|
zte
|
zxiptv_firmware
|
A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so remote attackers could use this vulnerability for account credential enumeration…
|
CWE-327 CWE-522
Use of a Broken or Risky Cryptographic Algorithm Insufficiently Protected Credentials
|
CVE-2020-6874
|
2024-11-21 14:36 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199117
|
5.3 |
MEDIUM
Network
|
zte
|
zxr10_2800-4_almpufb\(low\)_firmware
|
A ZTE product has a DoS vulnerability. Because the equipment couldn’t distinguish the attack packets and normal packets with valid http links, the remote attackers could use this vulnerability to cau…
|
NVD-CWE-noinfo
|
CVE-2020-6873
|
2024-11-21 14:36 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199118
|
9.8 |
CRITICAL
Network
|
os4ed
|
opensis
|
openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.
|
CWE-89
SQL Injection
|
CVE-2020-6637
|
2024-11-21 14:36 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199119
|
6.5 |
MEDIUM
Network
|
elastic
|
elasticsearch
|
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recent…
|
CWE-269
Improper Privilege Management
|
CVE-2020-7019
|
2024-11-21 14:36 |
2020-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199120
|
8.8 |
HIGH
Network
|
elastic
|
enterprise_search
|
Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API cre…
|
CWE-269
Improper Privilege Management
|
CVE-2020-7018
|
2024-11-21 14:36 |
2020-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|