|
196551
|
8.8 |
HIGH
Network
|
avaya
|
aura_messaging aura_communication_manager
|
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This vulnerability coul…
|
CWE-352
Origin Validation Error
|
CVE-2020-7029
|
2024-11-21 14:36 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196552
|
6.7 |
MEDIUM
Local
|
hpe
|
intelligent_provisioning service_pack_for_proliant smartstart_scripting_toolkit
|
A potential security vulnerability has been identified in HPE Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting ToolKit. The vulnerability could be locally exploited to allow arb…
|
NVD-CWE-noinfo
|
CVE-2020-7205
|
2024-11-21 14:36 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196553
|
4.8 |
MEDIUM
Network
|
elasticsearch oracle
|
kibana peoplesoft_enterprise_peopletools communications_billing_and_revenue_management communications_cloud_native_core_network_function_cloud_native_environment
|
Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-7016
|
2024-11-21 14:36 |
2020-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196554
|
6.7 |
MEDIUM
Network
|
elasticsearch oracle
|
kibana peoplesoft_enterprise_peopletools communications_billing_and_revenue_management communications_cloud_native_core_network_function_cloud_native_environment
|
In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive info…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7017
|
2024-11-21 14:36 |
2020-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196555
|
6.1 |
MEDIUM
Network
|
zte
|
r8500g4_firmware r5500g4_firmware r5300g4_firmware
|
The server management software module of ZTE has a storage XSS vulnerability. The attacker inserts some attack codes through the foreground login page, which will cause the user to execute the predef…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6872
|
2024-11-21 14:36 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196556
|
9.8 |
CRITICAL
Network
|
zte
|
r8500g4_firmware r5500g4_firmware r5300g4_firmware
|
The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the authentication of the server and execute some commands for high-level users. Thi…
|
CWE-287
Improper Authentication
|
CVE-2020-6871
|
2024-11-21 14:36 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196557
|
9.8 |
CRITICAL
Network
|
hp
|
nagios-plugins-hpilo
|
HP nagios plugin for iLO (nagios-plugins-hpilo v1.50 and earlier) has a php code injection vulnerability.
|
CWE-78
OS Command
|
CVE-2020-7206
|
2024-11-21 14:36 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196558
|
7.5 |
HIGH
Network
|
tableau
|
tableau_server
|
A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26, 2020, could allow access to sensitive information in log files.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-6938
|
2024-11-21 14:36 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196559
|
6.1 |
MEDIUM
Network
|
hp
|
icewall_sso_dfw icewall_sso_dgfw
|
A security vulnerability in HPE IceWall SSO Dfw and Dgfw (Domain Gateway Option) could be exploited remotely to cause a remote cross-site scripting (XSS). HPE has provided the following information t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7140
|
2024-11-21 14:36 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196560
|
7.8 |
HIGH
Local
|
mcafee
|
network_security_management
|
Exposure of Sensitive Information in McAfee Network Security Management (NSM) prior to 10.1.7.7 allows local users to gain unauthorised access to the root account via execution of carefully crafted c…
|
CWE-200
Information Exposure
|
CVE-2020-7284
|
2024-11-21 14:36 |
2020-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|