|
209911
|
7.5 |
HIGH
Network
|
ui w1.fi asus broadcom canon cisco dlink dell epson hp huawei nec netgear ruckussecurity tp-link zte zyxel microsoft fedoraproject debian canonical
|
unifi_controller hostapd rt-n11 adsl selphy_cp1200 wap150 wap351 wap131 dvg-n5412sp b1165nfw ew-m970a3t ep-101 xp-8500 xp-702 xp-340 xp-620 xp-320 x…
|
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualif…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-12695
|
2024-11-21 14:00 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209912
|
5.3 |
MEDIUM
Network
|
libreoffice fedoraproject opensuse
|
libreoffice fedora leap
|
LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who w…
|
NVD-CWE-Other
|
CVE-2020-12802
|
2024-11-21 14:00 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209913
|
8.8 |
HIGH
Network
|
realtek
|
adsl_router_soc_firmware
|
A security misconfiguration vulnerability exists in the SDK of some Realtek ADSL/PON Modem SoC firmware, which allows attackers using a default password to execute arbitrary commands remotely via the…
|
NVD-CWE-noinfo
|
CVE-2020-12773
|
2024-11-21 14:00 |
2020-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209914
|
7.5 |
HIGH
Network
|
perl netapp fedoraproject opensuse oracle
|
perl snap_creator_framework oncommand_workflow_automation fedora leap communications_eagle_lnp_application_processor sd-wan_edge enterprise_manager_base_platform communication…
|
regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-12723
|
2024-11-21 14:00 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209915
|
5.4 |
MEDIUM
Network
|
pydio
|
cells
|
Pydio Cells 2.0.4 allows any user to upload a profile image to the web application, including standard and shared user roles. These profile pictures can later be accessed directly with the generated …
|
CWE-79
Cross-site Scripting
|
CVE-2020-12849
|
2024-11-21 14:00 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209916
|
5.4 |
MEDIUM
Network
|
pydio
|
cells
|
In Pydio Cells 2.0.4, once an authenticated user shares a file selecting the create a public link option, a hidden shared user account is created in the backend with a random username. An anonymous u…
|
CWE-287
Improper Authentication
|
CVE-2020-12848
|
2024-11-21 14:00 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209917
|
6.1 |
MEDIUM
Network
|
pydio
|
cells
|
Pydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially malicious HTML and JavaScript code to personal folders or accessible cells.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12853
|
2024-11-21 14:00 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209918
|
8.1 |
HIGH
Network
|
pydio
|
cells
|
Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by uploading a custom generated ZIP file and leveraging…
|
CWE-22
Path Traversal
|
CVE-2020-12851
|
2024-11-21 14:00 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209919
|
6.8 |
MEDIUM
Network
|
pydio
|
cells
|
The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to validate the downloaded update package. The update process involves dow…
|
CWE-20
Improper Input Validation
|
CVE-2020-12852
|
2024-11-21 14:00 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209920
|
7.2 |
HIGH
Network
|
pydio
|
cells
|
Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with an administrator role. This console provides an administrator user with the po…
|
NVD-CWE-noinfo
|
CVE-2020-12847
|
2024-11-21 14:00 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|