|
200601
|
6.5 |
MEDIUM
Network
|
oklok_project
|
oklok
|
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) allows remote attackers to submit API requests using authenticated but unauthorized tokens, resulting in IDOR issue…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-8791
|
2024-11-21 14:39 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200602
|
9.8 |
CRITICAL
Network
|
oklok_project
|
oklok
|
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could…
|
CWE-307 CWE-521
mproper Restriction of Excessive Authentication Attempts Weak Password Requirements
|
CVE-2020-8790
|
2024-11-21 14:39 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200603
|
8.9 |
HIGH
Network
|
pega
|
platform
|
Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8775
|
2024-11-21 14:39 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200604
|
8.8 |
HIGH
Network
|
pega
|
pega_platform
|
Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8774
|
2024-11-21 14:39 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200605
|
8.9 |
HIGH
Network
|
pega
|
platform
|
The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8773
|
2024-11-21 14:39 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200606
|
9.8 |
CRITICAL
Network
|
huawei
|
ar3200_firmware
|
Huawei AR3200 products with versions of V200R007C00SPC900, V200R007C00SPCa00, V200R007C00SPCb00, V200R007C00SPCc00, V200R009C00SPC500 have an improper authentication vulnerability. Attackers need to …
|
CWE-287
Improper Authentication
|
CVE-2020-9068
|
2024-11-21 14:39 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200607
|
6.7 |
MEDIUM
Local
|
huawei
|
osd_firmware
|
Huawei OSD product with versions earlier than OSD_uwp_9.0.32.0 have a local privilege escalation vulnerability. An authenticated, local attacker can constructs a specific file path to exploit this vu…
|
NVD-CWE-noinfo
|
CVE-2020-9072
|
2024-11-21 14:39 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200608
|
5.5 |
MEDIUM
Local
|
juplink
|
rx4-1500_firmware
|
httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the unauthenticated setup3.htm endpoint from the local network.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-8798
|
2024-11-21 14:39 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200609
|
6.7 |
MEDIUM
Local
|
juplink
|
rx4-1500_firmware
|
Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line Injection), if the undocumented telnetd service is enabled an…
|
CWE-78
OS Command
|
CVE-2020-8797
|
2024-11-21 14:39 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200610
|
4.7 |
MEDIUM
Local
|
canonical apport_project
|
ubuntu_linux apport
|
Time-of-check Time-of-use Race Condition vulnerability on crash report ownership change in Apport allows for a possible privilege escalation opportunity. If fs.protected_symlinks is disabled, this ca…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2020-8833
|
2024-11-21 14:39 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|