|
209731
|
6.4 |
MEDIUM
Local
|
trendmicro
|
antivirus
|
Trend Micro Antivirus for Mac 2020 (Consumer) contains a race condition vulnerability in the Web Threat Protection Blocklist component, that if exploited, could allow an attacker to case a kernel pan…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2020-27014
|
2024-11-21 14:20 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209732
|
9.8 |
CRITICAL
Network
|
westerndigital
|
my_cloud_firmware
|
Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114 (issue 3 of 3).
|
CWE-22
Path Traversal
|
CVE-2020-27160
|
2024-11-21 14:20 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209733
|
9.8 |
CRITICAL
Network
|
westerndigital
|
my_cloud_firmware
|
Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western Digital My Cloud NAS devices prior to 5.04.114
|
CWE-78
OS Command
|
CVE-2020-27159
|
2024-11-21 14:20 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209734
|
9.8 |
CRITICAL
Network
|
westerndigital
|
my_cloud_firmware
|
Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114.
|
CWE-78
OS Command
|
CVE-2020-27158
|
2024-11-21 14:20 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209735
|
9.8 |
CRITICAL
Network
|
konzept-ix
|
publixone
|
A RemoteFunctions endpoint with missing access control in konzept-ix publiXone before 2020.015 allows attackers to disclose sensitive user information, send arbitrary e-mails, escalate the privileges…
|
NVD-CWE-noinfo
|
CVE-2020-27183
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209736
|
6.1 |
MEDIUM
Network
|
konzept-ix
|
publixone
|
Multiple cross-site scripting (XSS) vulnerabilities in konzept-ix publiXone before 2020.015 allow remote attackers to inject arbitrary JavaScript or HTML via appletError.jsp, job_jacket_detail.jsp, i…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27182
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209737
|
6.5 |
MEDIUM
Network
|
konzept-ix
|
publixone
|
A hardcoded AES key in CipherUtils.java in the Java applet of konzept-ix publiXone before 2020.015 allows attackers to craft password-reset tokens or decrypt server-side configuration files.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-27181
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209738
|
7.5 |
HIGH
Network
|
konzept-ix
|
publixone
|
konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-27180
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209739
|
9.8 |
CRITICAL
Network
|
konzept-ix
|
publixone
|
konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset tokens.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2020-27179
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209740
|
9.8 |
CRITICAL
Network
|
commscope
|
ruckus_vriot
|
Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorizat…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-26879
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|