|
199491
|
9.8 |
CRITICAL
Network
|
tp-link
|
wdr7400_firmware wdr7500_firmware wdr7660_firmware wdr7800_firmware wdr8400_firmware wdr8500_firmware wdr8600_firmware wdr8620_firmware wdr8640_firmware wdr8660_firmware
|
Buffer overflow in in the copy_msg_element function for the devDiscoverHandle server in the TP-Link WR and WDR series, including WDR7400, WDR7500, WDR7660, WDR7800, WDR8400, WDR8500, WDR8600, WDR8620…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-28877
|
2024-11-21 14:23 |
2020-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199492
|
5.3 |
MEDIUM
Network
|
bigbluebutton
|
bigbluebutton
|
web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name.
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2020-28954
|
2024-11-21 14:23 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199493
|
4.3 |
MEDIUM
Network
|
bigbluebutton
|
bigbluebutton
|
In BigBlueButton before 2.2.29, a user can vote more than once in a single poll.
|
NVD-CWE-noinfo
|
CVE-2020-28953
|
2024-11-21 14:23 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199494
|
7.5 |
HIGH
Network
|
rclone fedoraproject
|
rclone fedora
|
An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak passwords with much less entropy than advertised. The…
|
CWE-331 CWE-338
Insufficient Entropy Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2020-28924
|
2024-11-21 14:23 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199495
|
9.8 |
CRITICAL
Network
|
openwrt
|
openwrt
|
libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_strdup in util.c.
|
CWE-416
Use After Free
|
CVE-2020-28951
|
2024-11-21 14:23 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199496
|
7.8 |
HIGH
Local
|
php debian fedoraproject drupal
|
archive_tar debian_linux fedora drupal
|
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-28948
|
2024-11-21 14:23 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199497
|
5.5 |
MEDIUM
Local
|
linux fedoraproject debian
|
linux_kernel fedora debian_linux
|
An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack…
|
CWE-763
Release of Invalid Pointer or Reference
|
CVE-2020-28941
|
2024-11-21 14:23 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199498
|
6.1 |
MEDIUM
Network
|
misp
|
misp
|
In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28947
|
2024-11-21 14:23 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199499
|
4.3 |
MEDIUM
Network
|
primekey
|
ejbca
|
An issue exists in PrimeKey EJBCA before 7.4.3 when enrolling with EST while proxied through an RA over the Peers protocol. As a part of EJBCA's domain security model, the peer connector allows the r…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-28942
|
2024-11-21 14:23 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199500
|
6.1 |
MEDIUM
Network
|
palletsprojects
|
werkzeug
|
Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.
|
CWE-601
Open Redirect
|
CVE-2020-28724
|
2024-11-21 14:23 |
2020-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|