|
209981
|
5.3 |
MEDIUM
Network
|
ispyconnect
|
agent_dvr
|
iSpyConnect.com Agent DVR before 2.7.1.0 allows directory traversal.
|
CWE-22
Path Traversal
|
CVE-2020-13093
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209982
|
9.8 |
CRITICAL
Network
|
scikit-learn
|
scikit-learn
|
scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to the joblib.load() function, if __reduce__ makes an os.system call. NOTE: third …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-13092
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209983
|
9.8 |
CRITICAL
Network
|
numfocus
|
pandas
|
pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-13091
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209984
|
5.5 |
MEDIUM
Local
|
yaws
|
yaws
|
yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if running on an Erlang/OTP virtual machine with a version less than…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-12872
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209985
|
9.8 |
CRITICAL
Network
|
misp
|
misp-maltego
|
MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across users in a remote-transform use case.
|
NVD-CWE-noinfo
|
CVE-2020-12889
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209986
|
5.3 |
MEDIUM
Local
|
linux fedoraproject opensuse debian canonical netapp
|
linux_kernel fedora leap debian_linux ubuntu_linux cloud_backup element_software steelstore_cloud_integrated_storage solidfire hci_management_node active_iq_unified_mana…
|
The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-12888
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209987
|
7.8 |
HIGH
Local
|
sun-denshi
|
universal_forensic_extraction_device_firmware
|
Cellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command prompt via the Windows file dialog that is reachable via the Certificate-Based…
|
CWE-269
Improper Privilege Management
|
CVE-2020-12798
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209988
|
9.8 |
CRITICAL
Network
|
eq-3
|
homematic_ccu2_firmware ccu3_firmware
|
eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the we…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-12834
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209989
|
6.1 |
MEDIUM
Network
|
redhat
|
interchange
|
XSS in the admin help system admin/help.html and admin/quicklinks.html in Interchange 4.7.0 through 5.11.x allows remote attackers to steal credentials or data via browser JavaScript.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12685
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209990
|
5.4 |
MEDIUM
Network
|
rcos
|
submitty
|
Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a Teaching Fellow.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12882
|
2024-11-21 14:00 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|