|
199811
|
8.8 |
HIGH
Local
|
pcanalyser
|
pc_analyser
|
An issue was discovered in Devid Espenschied PC Analyser through 4.10. The PCADRVX64.SYS kernel driver exposes IOCTL functionality that allows low-privilege users to read and write arbitrary physical…
|
NVD-CWE-noinfo
|
CVE-2020-28922
|
2024-11-21 14:23 |
2020-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199812
|
8.8 |
HIGH
Local
|
pcanalyser
|
pc_analyser
|
An issue was discovered in Devid Espenschied PC Analyser through 4.10. The PCADRVX64.SYS kernel driver exposes IOCTL functionality that allows low-privilege users to read and write to arbitrary Model…
|
NVD-CWE-noinfo
|
CVE-2020-28921
|
2024-11-21 14:23 |
2020-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199813
|
5.3 |
MEDIUM
Network
|
sagemcom
|
f\@st_3486_router_firmware
|
Incorrect Access Control in the configuration backup path in SAGEMCOM F@ST3486 NET DOCSIS 3.0, software NET_4.109.0, allows remote unauthenticated users to download the router configuration file via …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-29138
|
2024-11-21 14:23 |
2020-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199814
|
5.4 |
MEDIUM
Network
|
ericsson
|
bscs_ix_r18_billing_\&_rating_mx bscs_ix_r18_billing_\&_rating_admx
|
In Ericsson BSCS iX R18 Billing & Rating iX R18, MX is a web base module in BSCS iX that is vulnerable to stored XSS via an Alert Dashboard comment. In most test cases, session hijacking was also pos…
|
CWE-79
Cross-site Scripting
|
CVE-2020-29144
|
2024-11-21 14:23 |
2020-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199815
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577).
|
CWE-79
Cross-site Scripting
|
CVE-2020-29137
|
2024-11-21 14:23 |
2020-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199816
|
6.5 |
MEDIUM
Network
|
cpanel
|
cpanel
|
In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-29136
|
2024-11-21 14:23 |
2020-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199817
|
4.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).
|
CWE-838
Inappropriate Encoding for Output Context
|
CVE-2020-29135
|
2024-11-21 14:23 |
2020-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199818
|
6.1 |
MEDIUM
Network
|
coremail_xt_project
|
coremail_xt
|
jsp/upload.jsp in Coremail XT 5.0 allows XSS via an uploaded personal signature, as demonstrated by a .jpg.html filename in the signImgFile parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29133
|
2024-11-21 14:23 |
2020-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199819
|
5.4 |
MEDIUM
Network
|
ericsson
|
bscs_ix_r18_billing_\&_rating_mx bscs_ix_r18_billing_\&_rating_admx
|
In Ericsson BSCS iX R18 Billing & Rating iX R18, ADMX is a web base module in BSCS iX that is vulnerable to stored XSS via the name or description field to a solutionUnitServlet?SuName=UserReferenceD…
|
CWE-79
Cross-site Scripting
|
CVE-2020-29145
|
2024-11-21 14:23 |
2020-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199820
|
4.3 |
MEDIUM
Network
|
libslirp_project debian fedoraproject
|
libslirp debian_linux fedora
|
slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-29130
|
2024-11-21 14:23 |
2020-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|