|
209041
|
7.8 |
HIGH
Local
|
pax
|
prolinos
|
An issue was discovered in ProlinOS through 2.4.161.8859R. An attacker with local code execution privileges as a normal user (MAINAPP) can escalate to root privileges by exploiting the setuid install…
|
CWE-269
Improper Privilege Management
|
CVE-2020-28046
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209042
|
6.8 |
MEDIUM
Physics
|
pax
|
prolinos
|
An attacker with physical access to a PAX Point Of Sale device with ProlinOS through 2.4.161.8859R can boot it in management mode, enable the XCB service, and then list, read, create, and overwrite f…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-28044
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209043
|
7.5 |
HIGH
Network
|
misp
|
misp
|
MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-28043
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209044
|
5.3 |
MEDIUM
Network
|
servicestack
|
servicestack
|
ServiceStack before 5.9.2 mishandles JWT signature verification unless an application has a custom ValidateToken function that establishes a valid minimum length for a signature.
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-28042
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209045
|
4.3 |
MEDIUM
Network
|
wordpress debian canonical
|
wordpress debian_linux ubuntu_linux
|
WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.
|
CWE-352
Origin Validation Error
|
CVE-2020-28040
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209046
|
9.1 |
CRITICAL
Network
|
wordpress debian canonical
|
wordpress debian_linux ubuntu_linux
|
is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.
|
NVD-CWE-noinfo
|
CVE-2020-28039
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209047
|
7.8 |
HIGH
Local
|
pax
|
prolinos
|
An unsigned-library issue was discovered in ProlinOS through 2.4.161.8859R. This OS requires installed applications and all system binaries to be signed either by the manufacturer or by the Point Of …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-28045
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209048
|
6.5 |
MEDIUM
Network
|
netgear
|
nighthawk_r7000_firmware
|
The SIP ALG implementation on NETGEAR Nighthawk R7000 1.0.9.64_10.2.64 devices allows remote attackers to communicate with arbitrary TCP and UDP services on a victim's intranet machine, if the victim…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-28041
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209049
|
6.1 |
MEDIUM
Network
|
wordpress fedoraproject debian
|
wordpress fedora debian_linux
|
WordPress before 5.5.2 allows stored XSS via post slugs.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28038
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209050
|
9.8 |
CRITICAL
Network
|
wordpress fedoraproject debian
|
wordpress fedora debian_linux
|
is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, lea…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2020-28037
|
2024-11-21 14:22 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|