|
196331
|
9.1 |
CRITICAL
Network
|
bosch
|
video_streaming_gateway divar_ip_2000_firmware divar_ip_5000_firmware
|
Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote attacker to retrieve and set arbitrary configuration data of the Video Streami…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-6769
|
2024-11-21 14:36 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196332
|
9.8 |
CRITICAL
Network
|
schmid-telecom
|
zi_620_v400_firmware
|
Schmid ZI 620 V400 VPN 090 routers allow an attacker to execute OS commands as root via shell metacharacters to an entry on the SSH subcommand menu, as demonstrated by ping.
|
CWE-78
OS Command
|
CVE-2020-6760
|
2024-11-21 14:36 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196333
|
6.5 |
MEDIUM
Network
|
sos-berlin
|
jobscheduler
|
An XML External Entity (XEE) vulnerability exists in the JOC Cockpit component of SOS JobScheduler 1.12 and 1.13.2 allows attackers to read files from the server via an entity declaration in any of t…
|
CWE-776
XML Entity Expansion
|
CVE-2020-6856
|
2024-11-21 14:36 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196334
|
6.5 |
MEDIUM
Network
|
sos-berlin
|
jobscheduler
|
A large or infinite loop vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to parameterize housekeeping jobs in a way that exhausts system resources and …
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-6855
|
2024-11-21 14:36 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196335
|
6.5 |
MEDIUM
Network
|
bosch
|
video_management_system_viewer video_management_system
|
A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated remote attacker to read arbitrary files from the Central Server. This affects Bo…
|
CWE-22
Path Traversal
|
CVE-2020-6767
|
2024-11-21 14:36 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196336
|
5.4 |
MEDIUM
Network
|
sos-berlin
|
jobscheduler
|
A cross-site scripting (XSS) vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to inject arbitrary web script or HTML via JSON properties available from …
|
CWE-79
Cross-site Scripting
|
CVE-2020-6854
|
2024-11-21 14:36 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196337
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.
|
NVD-CWE-noinfo
|
CVE-2020-6833
|
2024-11-21 14:36 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196338
|
9.8 |
CRITICAL
Network
|
dotcms
|
dotcms
|
dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2020-6754
|
2024-11-21 14:36 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196339
|
9.8 |
CRITICAL
Network
|
automationdirect
|
c-more_ea9-rhi_firmware c-more_ea9-t6cl-r_firmware c-more_ea9-t6cl_firmware c-more_ea9-t7cl-r_firmware c-more_ea9-t7cl_firmware c-more_ea9-t8cl_firmware c-more_ea9-t10cl_firmware
|
It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an attacker to remotely access the C-More Touch Panels EA9 series: firmware versio…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-6969
|
2024-11-21 14:36 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196340
|
7.5 |
HIGH
Network
|
opensuse
|
wicked leap
|
An ni_dhcp4_parse_response memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets without a message type option.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-7216
|
2024-11-21 14:36 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|