|
209781
|
7.5 |
HIGH
Network
|
zohocorp
|
manageengine_opmanager
|
In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
|
NVD-CWE-noinfo
|
CVE-2020-11527
|
2024-11-21 13:58 |
2020-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209782
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_adselfservice_plus
|
Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-11518
|
2024-11-21 13:58 |
2020-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209783
|
7.4 |
HIGH
Network
|
gnu debian opensuse canonical fedoraproject
|
gnutls debian_linux leap ubuntu_linux fedora
|
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' by…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-11501
|
2024-11-21 13:58 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209784
|
7.5 |
HIGH
Network
|
zoom
|
meetings
|
Zoom Client for Meetings through 4.6.9 uses the ECB mode of AES for video and audio encryption. Within a meeting, all participants use a single 128-bit key.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-11500
|
2024-11-21 13:58 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209785
|
6.1 |
MEDIUM
Network
|
firmware_analysis_and_comparison_tool_project
|
firmware_analysis_and_comparison_tool
|
Firmware Analysis and Comparison Tool (FACT) 3 has Stored XSS when updating analysis details via a localhost web request, as demonstrated by mishandling of the tags and version fields in helperFuncti…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11499
|
2024-11-21 13:58 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209786
|
8.8 |
HIGH
Network
|
slack
|
nebula
|
Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code in the context of the root user via tun_darwin.go or tun_windows.go. A user can…
|
CWE-22
Path Traversal
|
CVE-2020-11498
|
2024-11-21 13:58 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209787
|
4.4 |
MEDIUM
Local
|
linux opensuse debian canonical
|
linux_kernel leap debian_linux ubuntu_linux
|
An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.2. It allows attackers to read uninitialized can_frame data, potentially containing sensitive infor…
|
CWE-908 CWE-909
Use of Uninitialized Resource Missing Initialization of Resource
|
CVE-2020-11494
|
2024-11-21 13:58 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209788
|
4.9 |
MEDIUM
Network
|
zevenet
|
zen_load_balancer
|
Monitoring::Logs in Zen Load Balancer 3.10.1 allows remote authenticated admins to conduct absolute path traversal attacks, as demonstrated by a filelog=/etc/shadow request to index.cgi.
|
CWE-22
Path Traversal
|
CVE-2020-11491
|
2024-11-21 13:58 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209789
|
7.2 |
HIGH
Network
|
zevenet
|
zen_load_balancer
|
Manage::Certificates in Zen Load Balancer 3.10.1 allows remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the index.cgi cert_issuer, cert_division, cert_organiz…
|
CWE-78
OS Command
|
CVE-2020-11490
|
2024-11-21 13:58 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209790
|
6.1 |
MEDIUM
Network
|
bell
|
home_hub_3000_firmware
|
An issue was discovered on Bell HomeHub 3000 SG48222070 devices. There is XSS related to the email field and the login page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11448
|
2024-11-21 13:57 |
2023-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|