|
209241
|
8.2 |
HIGH
Local
|
freebsd omniosce openindiana netapp
|
freebsd omnios openindiana clustered_data_ontap
|
bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demons…
|
CWE-862
Missing Authorization
|
CVE-2020-24718
|
2024-11-21 14:15 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209242
|
7.1 |
HIGH
Local
|
mitel
|
micontact_center_business
|
The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allo…
|
CWE-79 CWE-20
Cross-site Scripting Improper Input Validation
|
CVE-2020-24692
|
2024-11-21 14:15 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209243
|
8.8 |
HIGH
Network
|
openmrs
|
htmlformentry
|
A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS. By leveraging path traversal, a malicious Velocity Template Lan…
|
CWE-22
Path Traversal
|
CVE-2020-24621
|
2024-11-21 14:15 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209244
|
5.3 |
MEDIUM
Network
|
pexip
|
pexip_infinity
|
Pexip Infinity before 24.1 has Improper Input Validation, leading to temporary denial of service via SIP.
|
CWE-20
Improper Input Validation
|
CVE-2020-24615
|
2024-11-21 14:15 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209245
|
5.3 |
MEDIUM
Network
|
mitel
|
micloud_management_portal
|
Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to retrieve sensitive information due to insufficient access control.
|
NVD-CWE-noinfo
|
CVE-2020-24595
|
2024-11-21 14:15 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209246
|
9.6 |
CRITICAL
Network
|
mitel
|
micloud_management_portal
|
Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an …
|
CWE-79
Cross-site Scripting
|
CVE-2020-24594
|
2024-11-21 14:15 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209247
|
7.2 |
HIGH
Network
|
mitel
|
micloud_management_portal
|
Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and access user credentials due to improper input validation.
|
CWE-20 CWE-89
Improper Input Validation SQL Injection
|
CVE-2020-24593
|
2024-11-21 14:15 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209248
|
5.3 |
MEDIUM
Network
|
mitel
|
micloud_management_portal
|
Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to view system information due to insufficient output sanitization.
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2020-24592
|
2024-11-21 14:15 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209249
|
9.8 |
CRITICAL
Network
|
hpe
|
utility_computing_service_meter
|
Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execution in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.
|
CWE-22
Path Traversal
|
CVE-2020-24626
|
2024-11-21 14:15 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209250
|
7.5 |
HIGH
Network
|
hpe
|
utility_computing_service_meter
|
Unathenticated directory traversal in the ReceiverServlet class doGet() method can lead to arbitrary file reads in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.
|
CWE-22
Path Traversal
|
CVE-2020-24625
|
2024-11-21 14:15 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|