|
210361
|
8.1 |
HIGH
Adjacent
|
insulet
|
omnipod_insulin_management_system_firmware
|
Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wireless RF with an Insulet manufactured Personal Diabetes Manager device. This wi…
|
NVD-CWE-Other
|
CVE-2020-10627
|
2024-11-21 13:55 |
2021-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210362
|
7.5 |
HIGH
Network
|
replicated
|
replicated_classic
|
Replicated Classic 2.x versions have an improperly secured API that exposes sensitive data from the Replicated Admin Console configuration. An attacker with network access to the Admin Console port (…
|
NVD-CWE-noinfo
|
CVE-2020-10590
|
2024-11-21 13:55 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210363
|
4.3 |
MEDIUM
Network
|
elastic redhat
|
kibana openshift_container_platform
|
It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker t…
|
-
|
CVE-2020-10743
|
2024-11-21 13:55 |
2021-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210364
|
6.0 |
MEDIUM
Local
|
linux redhat
|
linux_kernel enterprise_linux
|
A flaw was found in the Linux kernel. An index buffer overflow during Direct IO write leading to the NFS client to crash. In some cases, a reach out of the index after one memory allocation by kmallo…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10742
|
2024-11-21 13:55 |
2021-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210365
|
9.8 |
CRITICAL
Network
|
sangoma
|
restapps
|
The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote code execution via a URL variable to an AMI command.
|
CWE-77
Command Injection
|
CVE-2020-10666
|
2024-11-21 13:55 |
2021-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210366
|
5.5 |
MEDIUM
Local
|
redhat debian
|
ansible_engine debian_linux
|
A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since …
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-10729
|
2024-11-21 13:55 |
2021-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210367
|
6.5 |
MEDIUM
Network
|
redhat theforeman
|
satellite_capsule satellite foreman_ansible
|
A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view. This flaw allows a malicious Satellite user to scan through the Job Invoc…
|
NVD-CWE-Other
|
CVE-2020-10716
|
2024-11-21 13:55 |
2021-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210368
|
7.1 |
HIGH
Local
|
redhat
|
ansible_tower
|
A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authentication. This flaw allows an attacker to obtain a…
|
CWE-287 CWE-613
Improper Authentication Insufficient Session Expiration
|
CVE-2020-10709
|
2024-11-21 13:55 |
2021-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210369
|
6.5 |
MEDIUM
Network
|
redhat
|
libvirt
|
A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for th…
|
-
|
CVE-2020-10701
|
2024-11-21 13:55 |
2021-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210370
|
3.3 |
LOW
Local
|
redhat
|
ansible_tower
|
A flaw was found in Ansible Tower when running jobs. This flaw allows an attacker to access the stdout of the executed jobs which are run from other organizations. Some sensible data can be disclosed…
|
NVD-CWE-Other
|
CVE-2020-10698
|
2024-11-21 13:55 |
2021-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|