|
196411
|
6.1 |
MEDIUM
Network
|
teltonika-networks
|
trb245_firmware
|
Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.04.3 allows an unauthenticated attacker to conduct reflected cross-site scripting via a crafted ‘action’ or ‘pkg_name’ parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5785
|
2024-11-21 14:34 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196412
|
6.5 |
MEDIUM
Network
|
teltonika-networks
|
trb245_firmware
|
Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the application to perform HTTP GET requests to arbitrary URLs.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-5784
|
2024-11-21 14:34 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196413
|
4.4 |
MEDIUM
Local
|
dell
|
xps_13_9370_firmware
|
Dell XPS 13 9370 BIOS versions prior to 1.13.1 contains an Improper Exception Handling vulnerability. A local attacker with physical access could exploit this vulnerability to prevent the system from…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-5387
|
2024-11-21 14:34 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196414
|
7.5 |
HIGH
Network
|
f5
|
big-iq_centralized_management big-ip_local_traffic_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_analytics big-ip_access_policy_manager big…
|
In BIG-IP 15.0.0-15.1.0.4, 14.1.0-14.1.2.7, 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2 and BIG-IQ 5.2.0-7.1.0, unauthenticated attackers can cause disruption of service via undisclosed met…
|
NVD-CWE-noinfo
|
CVE-2020-5930
|
2024-11-21 14:34 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196415
|
5.9 |
MEDIUM
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_web_application_firewall big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_man…
|
In versions 13.0.0-13.0.0 HF2, 12.1.0-12.1.2 HF1, and 11.6.1-11.6.2, BIG-IP platforms with Cavium Nitrox SSL hardware acceleration cards, a Virtual Server configured with a Client SSL profile, and us…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-5929
|
2024-11-21 14:34 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196416
|
6.4 |
MEDIUM
Adjacent
|
checkpoint
|
ica_management_portal
|
Check Point Security Management's Internal CA web management before Jumbo HFAs R80.10 Take 278, R80.20 Take 160, R80.30 Take 210, and R80.40 Take 38, can be manipulated to run commands as a high priv…
|
CWE-20
Improper Input Validation
|
CVE-2020-6020
|
2024-11-21 14:34 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196417
|
5.4 |
MEDIUM
Network
|
ignitenet
|
helios_glinq
|
In IgniteNet HeliOS GLinq v2.2.1 r2961, the login functionality does not contain any CSRF protection mechanisms.
|
CWE-352
Origin Validation Error
|
CVE-2020-5783
|
2024-11-21 14:34 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196418
|
6.5 |
MEDIUM
Network
|
ignitenet
|
helios_glinq
|
In IgniteNet HeliOS GLinq v2.2.1 r2961, if a user logs in and sets the ‘wan_type’ parameter, the wan interface for the device will become unreachable, which results in a denial of service condition f…
|
NVD-CWE-noinfo
|
CVE-2020-5782
|
2024-11-21 14:34 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196419
|
4.3 |
MEDIUM
Network
|
ignitenet
|
helios_glinq
|
In IgniteNet HeliOS GLinq v2.2.1 r2961, the langSelection parameter is stored in the luci configuration file (/etc/config/luci) by the authenticator.htmlauth function. When modified with arbitrary ja…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5781
|
2024-11-21 14:34 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196420
|
6.5 |
MEDIUM
Network
|
vmware oracle netapp
|
spring_framework flexcube_private_banking weblogic_server insurance_rules_palette endeca_information_discovery_integrator retail_predictive_application_server retail_order_broker
|
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depe…
|
NVD-CWE-noinfo
|
CVE-2020-5421
|
2024-11-21 14:34 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|