|
198901
|
8.7 |
HIGH
Network
|
dell
|
emc_avamar_server emc_integrated_data_protection_appliance
|
Dell EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a Path Traversal Vulnerability in PDM. A remote user could potentially exploit this vulnerability, to gain unauthorized write access to the …
|
CWE-22
Path Traversal
|
CVE-2020-29494
|
2024-11-21 14:24 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198902
|
5.4 |
MEDIUM
Network
|
simplcommerce
|
simplcommerce
|
SimplCommerce 1.0.0-rc uses the Bootbox.js library, which allows creation of programmatic dialog boxes using Bootstrap modals. The Bootbox.js library intentionally does not perform any sanitization o…
|
CWE-79
Cross-site Scripting
|
CVE-2020-29587
|
2024-11-21 14:24 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198903
|
10.0 |
CRITICAL
Network
|
dell
|
emc_avamar_server emc_integrated_data_protection_appliance
|
DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, l…
|
CWE-78
OS Command
|
CVE-2020-29495
|
2024-11-21 14:24 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198904
|
9.8 |
CRITICAL
Network
|
dell
|
emc_avamar_server emc_integrated_data_protection_appliance
|
DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading t…
|
CWE-89
SQL Injection
|
CVE-2020-29493
|
2024-11-21 14:24 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198905
|
6.7 |
MEDIUM
Local
|
dell
|
emc_powerstore_firmware
|
Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit th…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-29502
|
2024-11-21 14:24 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198906
|
6.7 |
MEDIUM
Local
|
dell
|
emc_powerstore_firmware
|
Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit th…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-29501
|
2024-11-21 14:24 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198907
|
6.7 |
MEDIUM
Local
|
dell
|
emc_powerstore_firmware
|
Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore T environments. A locally authenticated attacker could potentially exploit this v…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-29500
|
2024-11-21 14:24 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198908
|
6.5 |
MEDIUM
Network
|
dell
|
emc_unity_operating_environment emc_unity_vsa_operating_environment emc_unity_xt_operating_environment
|
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a Denial of Service vulnerability on NAS Servers with NFS exports. A remote authenticated attacker could potentially exp…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-29490
|
2024-11-21 14:24 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198909
|
6.7 |
MEDIUM
Local
|
dell
|
emc_unity_operating_environment emc_unity_vsa_operating_environment emc_unity_xt_operating_environment
|
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contains a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-29489
|
2024-11-21 14:24 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198910
|
8.1 |
HIGH
Network
|
orangehrm
|
orangehrm
|
SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBuzzPlugin/lib/dao/BuzzDao.php loadMorePostsForm[pro…
|
CWE-89
SQL Injection
|
CVE-2020-29437
|
2024-11-21 14:24 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|