|
196631
|
7.5 |
HIGH
Local
|
insyde siemens
|
insydeh2o ruggedcom_ape1808_firmware simatic_field_pg_m6_firmware simatic_ipc127e_firmware simatic_ipc227g_firmware simatic_ipc277g_firmware simatic_itp1000_firmware simatic_ipc4…
|
A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariab…
|
NVD-CWE-noinfo
|
CVE-2020-5953
|
2024-11-21 14:34 |
2022-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196632
|
7.5 |
HIGH
Network
|
insyde
|
insydeh2o
|
An issue was discovered in SdLegacySmm in Insyde InsydeH2O with kernel 5.1 before 05.15.11, 5.2 before 05.25.11, 5.3 before 05.34.11, and 5.4 before 05.42.11. The software SMI handler allows untruste…
|
CWE-20
Improper Input Validation
|
CVE-2020-5956
|
2024-11-21 14:34 |
2022-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196633
|
9.8 |
CRITICAL
Network
|
insyde
|
insydeh2o_uefi_bios
|
An issue was discovered in Int15MicrocodeSmm in Insyde InsydeH2O before 2021-10-14 on Intel client chipsets. A caller may be able to escalate privileges.
|
NVD-CWE-noinfo
|
CVE-2020-5955
|
2024-11-21 14:34 |
2021-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196634
|
5.4 |
MEDIUM
Network
|
sixapart
|
movable_type
|
Cross-site scripting vulnerability in Movable Type Movable Type Premium 1.37 and earlier and Movable Type Premium Advanced 1.37 and earlier allows a remote authenticated attacker to inject an arbitra…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5669
|
2024-11-21 14:34 |
2021-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196635
|
6.8 |
MEDIUM
Network
|
dell
|
emc_openmanage_enterprise
|
Dell EMC OpenManage Enterprise (OME) versions prior to 3.4 contain an arbitrary file overwrite vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this…
|
CWE-22
Path Traversal
|
CVE-2020-5370
|
2024-11-21 14:34 |
2021-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196636
|
5.9 |
MEDIUM
Network
|
tenable
|
nessus_amazon_machine_image
|
Nessus AMI versions 8.12.0 and earlier were found to either not validate, or incorrectly validate, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-5812
|
2024-11-21 14:34 |
2021-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196637
|
8.8 |
HIGH
Network
|
infoscience
|
elc_analytics logstorage
|
Logstorage version 8.0.0 and earlier, and ELC Analytics version 3.0.0 and earlier allow remote attackers to execute arbitrary OS commands via a specially crafted log file.
|
CWE-78
OS Command
|
CVE-2020-5626
|
2024-11-21 14:34 |
2021-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196638
|
6.0 |
MEDIUM
Network
|
vmware
|
spring_cloud_task
|
In applications using Spring Cloud Task 2.2.4.RELEASE and below, may be vulnerable to SQL injection when exercising certain lookup queries in the TaskExplorer.
|
CWE-89
SQL Injection
|
CVE-2020-5428
|
2024-11-21 14:34 |
2021-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196639
|
7.2 |
HIGH
Network
|
vmware
|
spring_cloud_data_flow
|
In Spring Cloud Data Flow, versions 2.6.x prior to 2.6.5, versions 2.5.x prior 2.5.4, an application is vulnerable to SQL injection when requesting task execution.
|
CWE-89
SQL Injection
|
CVE-2020-5427
|
2024-11-21 14:34 |
2021-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196640
|
7.5 |
HIGH
Network
|
nec
|
univerge_sv9500_firmware univerge_sv8500_firmware
|
Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to access the remote system maintenance feature an…
|
CWE-287
Improper Authentication
|
CVE-2020-5686
|
2024-11-21 14:34 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|