|
197591
|
6.5 |
MEDIUM
Network
|
mongodb
|
mongodb
|
A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects MongoDB Server v3.6 versions prior to 3.6.21…
|
NVD-CWE-Other
|
CVE-2020-7929
|
2024-11-21 14:38 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197592
|
7.0 |
HIGH
Local
|
opensuse
|
cyrus-sasl
|
A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows local attackers to escalate to root. This issue affects: openSUSE Factory cyrus-sasl version 2.1.27-4…
|
-
|
CVE-2020-8032
|
2024-11-21 14:38 |
2021-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197593
|
4.3 |
MEDIUM
Network
|
nextcloud
|
deck
|
Nextcloud Deck before 1.0.2 suffers from an insecure direct object reference (IDOR) vulnerability that permits users with a duplicate user identifier to access deck data of a previous deleted user.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-8297
|
2024-11-21 14:38 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197594
|
4.4 |
MEDIUM
Local
|
suse
|
caas_platform
|
A Insecure Temporary File vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to leak the bootstrapToken or modify the configuration file before it is processed, leading to arbitr…
|
-
|
CVE-2020-8030
|
2024-11-21 14:38 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197595
|
4.0 |
MEDIUM
Local
|
suse
|
caas_platform
|
A Incorrect Permission Assignment for Critical Resource vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to gain access to the kublet key. This issue affects: SUSE CaaS Platfor…
|
-
|
CVE-2020-8029
|
2024-11-21 14:38 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197596
|
5.4 |
MEDIUM
Network
|
opensuse
|
open_build_service
|
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Open Build Service allows remote attackers to store JS code in markdown that is not properly es…
|
-
|
CVE-2020-8031
|
2024-11-21 14:38 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197597
|
6.6 |
MEDIUM
Local
|
opensuse
|
openldap2
|
A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to…
|
-
|
CVE-2020-8027
|
2024-11-21 14:38 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197598
|
4.9 |
MEDIUM
Network
|
lenovo
|
xclarity_administrator
|
An internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 discovered the Windows OS credentials provided by the LXCA user to perform driver updates of managed …
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-8355
|
2024-11-21 14:38 |
2021-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197599
|
5.4 |
MEDIUM
Network
|
nextcloud
|
nextcloud_server
|
A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when saving a 'javascript:' URL in markdown format.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8294
|
2024-11-21 14:38 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197600
|
8.8 |
HIGH
Adjacent
|
adt
|
lifeshield_diy_hd_video_doorbell_firmware
|
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in HTTP interface of ADT LifeShield DIY HD Video Doorbell allows an attacker on the same network to e…
|
CWE-77
Command Injection
|
CVE-2020-8101
|
2024-11-21 14:38 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|