|
196481
|
8.8 |
HIGH
Network
|
teltonika-networks
|
trb245_firmware
|
Improper Access Control in Teltonika firmware TRB2_R_00.02.04.01 allows a low privileged user to perform unauthorized write operations.
|
CWE-269
Improper Privilege Management
|
CVE-2020-5773
|
2024-11-21 14:34 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196482
|
7.5 |
HIGH
Network
|
teltonika-networks
|
trb245_firmware
|
Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious package file.
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-5772
|
2024-11-21 14:34 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196483
|
7.5 |
HIGH
Network
|
teltonika-networks
|
trb245_firmware
|
Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious backup archive.
|
CWE-20
Improper Input Validation
|
CVE-2020-5771
|
2024-11-21 14:34 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196484
|
8.8 |
HIGH
Network
|
teltonika-networks
|
trb245_firmware
|
Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
|
CWE-352
Origin Validation Error
|
CVE-2020-5770
|
2024-11-21 14:34 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196485
|
5.7 |
MEDIUM
Network
|
vmware
|
tanzu_application_service_for_virtual_machines operations_manager
|
VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains an App Autoscaler that logs the UAA admin passwor…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-5414
|
2024-11-21 14:34 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196486
|
9.8 |
CRITICAL
Network
|
vmware oracle
|
spring_integration flexcube_private_banking retail_merchandising_system banking_virtual_account_management banking_credit_facilities_process_management banking_corporate_lending_proces…
|
Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered classes are resolved on d…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-5413
|
2024-11-21 14:34 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196487
|
8.8 |
HIGH
Network
|
vmware
|
gemfire tanzu_gemfire_for_virtual_machines
|
VMware GemFire versions prior to 9.10.0, 9.9.2, 9.8.7, and 9.7.6, and VMware Tanzu GemFire for VMs versions prior to 1.11.1 and 1.10.2, when deployed without a SecurityManager, contain a JMX service …
|
CWE-862
Missing Authorization
|
CVE-2020-5396
|
2024-11-21 14:34 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196488
|
8.4 |
HIGH
Local
|
rsa
|
multifactor_authentication_agent
|
Authentication Bypass Vulnerability RSA MFA Agent 2.0 for Microsoft Windows contains an Authentication Bypass vulnerability. A local unauthenticated attacker could potentially exploit this vulnerabil…
|
CWE-287
Improper Authentication
|
CVE-2020-5384
|
2024-11-21 14:34 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196489
|
7.8 |
HIGH
Local
|
toyota
|
global_techstream
|
Global TechStream (GTS) for TOYOTA dealers version 15.10.032 and earlier allows an attacker to cause a denial-of-service (DoS) condition and execute arbitrary code via unspecified vectors.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-5610
|
2024-11-21 14:34 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196490
|
8.8 |
HIGH
Network
|
grandstream
|
ht801_firmware ht802_firmware ht812_firmware ht814_firmware ht818_firmware ht813_firmware
|
Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can obtain a root shell by correctly answering a challenge prompt.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-5763
|
2024-11-21 14:34 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|