|
209791
|
6.5 |
MEDIUM
Network
|
br-automation
|
sitemanager
|
A local file inclusion vulnerability in B&R SiteManager versions <9.2.620236042 allows authenticated users to read sensitive files from SiteManager instances.
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2020-11641
|
2024-11-21 13:58 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209792
|
9.8 |
CRITICAL
Network
|
zabbix opensuse debian
|
zabbix leap backports_sle debian_linux
|
Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.
|
NVD-CWE-noinfo
|
CVE-2020-11800
|
2024-11-21 13:58 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209793
|
9.8 |
CRITICAL
Network
|
pexip
|
reverse_proxy_and_turn_server pexip_infinity
|
Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.
|
CWE-20
Improper Input Validation
|
CVE-2020-11805
|
2024-11-21 13:58 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209794
|
9.8 |
CRITICAL
Network
|
microfocus
|
operation_bridge_reporter
|
Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to execute arbitrary code on affec…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-11856
|
2024-11-21 13:58 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209795
|
9.8 |
CRITICAL
Network
|
microfocus
|
operation_bridge_reporter
|
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to access the OBR host as a non-adm…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-11857
|
2024-11-21 13:58 |
2020-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209796
|
7.8 |
HIGH
Local
|
microfocus
|
operation_bridge_reporter
|
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow local attackers on the OBR host to execute code with…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-11855
|
2024-11-21 13:58 |
2020-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209797
|
7.8 |
HIGH
Local
|
microfocus
|
operations_agent
|
Unauthorized escalation of local privileges vulnerability on Micro Focus Operation Agent, affecting all versions prior to versions 12.11. The vulnerability could be exploited to escalate the local pr…
|
NVD-CWE-noinfo
|
CVE-2020-11861
|
2024-11-21 13:58 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209798
|
8.8 |
HIGH
Network
|
titanhq
|
spamtitan
|
An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page mailqueue.php, code injection can occur. The input for this parameter is provided…
|
CWE-94
Code Injection
|
CVE-2020-11804
|
2024-11-21 13:58 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209799
|
8.8 |
HIGH
Network
|
titanhq
|
spamtitan
|
An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could lead to PHP code evaluation server-side, because the…
|
CWE-94
Code Injection
|
CVE-2020-11803
|
2024-11-21 13:58 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209800
|
6.5 |
MEDIUM
Network
|
titanhq
|
spamtitan
|
An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.php, would allow an attacker to retrieve the contents of arbitrary files. The u…
|
CWE-22
Path Traversal
|
CVE-2020-11700
|
2024-11-21 13:58 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|