|
209671
|
9.8 |
CRITICAL
Network
|
moog
|
exvf5c-2_firmware exvp7c2-3_firmware
|
The administration console of the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units features a 'statusbroadcast' command that can spawn a given process repeatedly at a certain time interval as 'root'. One…
|
CWE-78
OS Command
|
CVE-2020-24054
|
2024-11-21 14:14 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209672
|
7.5 |
HIGH
Network
|
moog
|
exvf5c-2_firmware exvp7c2-3_firmware
|
Moog EXO Series EXVF5C-2 and EXVP7C2-3 units have a hardcoded credentials vulnerability. This could cause a confidentiality issue when using the FTP, Telnet, or SSH protocols.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-24053
|
2024-11-21 14:14 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209673
|
9.1 |
CRITICAL
Network
|
moog
|
exvf5c-2_firmware exvp7c2-3_firmware
|
Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unauthenticated users to read arbitrary files via a crafted Document Type Definition…
|
CWE-611
XXE
|
CVE-2020-24052
|
2024-11-21 14:14 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209674
|
9.8 |
CRITICAL
Network
|
moog
|
exvf5c-2_firmware exvp7c2-3_firmware
|
The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the ONVIF interoperability IP-based physical security protocol, which requires authentication for some of its operations. It was found that th…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-24051
|
2024-11-21 14:14 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209675
|
7.5 |
HIGH
Network
|
hashicorp
|
vault-ssh-helper
|
HashiCorp vault-ssh-helper up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet in which a host's network interface was located, rather than the specific IP add…
|
CWE-20
Improper Input Validation
|
CVE-2020-24359
|
2024-11-21 14:14 |
2020-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209676
|
9.8 |
CRITICAL
Network
|
student_management_system_project
|
student_management_system
|
Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".
|
CWE-89
SQL Injection
|
CVE-2020-23935
|
2024-11-21 14:14 |
2020-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209677
|
9.8 |
CRITICAL
Network
|
phpgurukul
|
vehicle_parking_management_system
|
PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".
|
CWE-89
SQL Injection
|
CVE-2020-23936
|
2024-11-21 14:14 |
2020-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209678
|
7.5 |
HIGH
Network
|
icinga debian suse
|
icinga_web_2 debian_linux package_hub
|
Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web …
|
CWE-22
Path Traversal
|
CVE-2020-24368
|
2024-11-21 14:14 |
2020-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209679
|
7.1 |
HIGH
Local
|
linux canonical opensuse oracle starwindsoftware
|
linux_kernel ubuntu_linux leap sd-wan_edge starwind_virtual_san
|
In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs be…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-24394
|
2024-11-21 14:14 |
2020-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209680
|
7.5 |
HIGH
Network
|
gunet
|
open_eclass_platform
|
GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensure that the web server blocks directory listings, …
|
CWE-200
Information Exposure
|
CVE-2020-24381
|
2024-11-21 14:14 |
2020-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|