|
201671
|
5.3 |
MEDIUM
Network
|
microfocus
|
service_manager
|
Login filter can access configuration files vulnerability in Micro Focus Service Manager (Web Tier), affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to all…
|
NVD-CWE-noinfo
|
CVE-2020-9518
|
2024-11-21 14:40 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201672
|
5.3 |
MEDIUM
Network
|
microfocus
|
service_manager
|
HTTP methods reveled in Web services vulnerability in Micro Focus Service manager (server), affecting versions 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. The vulnerability could be exploit…
|
NVD-CWE-noinfo
|
CVE-2020-9519
|
2024-11-21 14:40 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201673
|
7.8 |
HIGH
Local
|
fortinet
|
forticlient forticlient_virtual_private_network
|
An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the directory in which FortiClientOnlineInstaller.exe and …
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-9290
|
2024-11-21 14:40 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201674
|
7.8 |
HIGH
Local
|
fortinet
|
forticlient_emergency_management_server
|
An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with control over the directory in which FortiClientEMSOnlineInstaller.exe resides t…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-9287
|
2024-11-21 14:40 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201675
|
8.3 |
HIGH
Network
|
openstack
|
manila
|
OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attack…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-9543
|
2024-11-21 14:40 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201676
|
7.5 |
HIGH
Network
|
beckhoff
|
bk9000_firmware
|
A Denial-of-Service vulnerability exists in BECKHOFF Ethernet TCP/IP Bus Coupler BK9000. After an attack has occurred, the device's functionality can be restored by rebooting.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-9464
|
2024-11-21 14:40 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201677
|
8.8 |
HIGH
Network
|
phoenixcontact
|
tc_router_3002t-4g_firmware tc_router_2002t-3g_firmware tc_router_3002t-4g_vzw_firmware tc_router_3002t-4g_att_firmware tc_cloud_client_1002-4g_firmware tc_cloud_client_1002-txtx_firmw…
|
PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.0…
|
CWE-78
OS Command
|
CVE-2020-9436
|
2024-11-21 14:40 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201678
|
7.5 |
HIGH
Network
|
phoenixcontact
|
tc_router_3002t-4g_firmware tc_router_2002t-3g_firmware tc_router_3002t-4g_vzw_firmware tc_router_3002t-4g_att_firmware tc_cloud_client_1002-4g_firmware tc_cloud_client_1002-txtx_firmw…
|
PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.0…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-9435
|
2024-11-21 14:40 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201679
|
8.8 |
HIGH
Network
|
tibco
|
spotfire_server spotfire_analytics_platform_for_aws
|
The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vulnerability that theoretically allows an attacker …
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-9408
|
2024-11-21 14:40 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201680
|
6.1 |
MEDIUM
Network
|
ckeditor webspellchecker fedoraproject
|
ckeditor webspellchecker fedora
|
A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML el…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9440
|
2024-11-21 14:40 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|