|
196941
|
7.5 |
HIGH
Network
|
sap
|
netweaver_internet_communication_manager_\(kernel\) netweaver_internet_communication_manager_\(krnl32nuc\) netweaver_internet_communication_manager_\(krnl32uc\) netweaver_internet_communicat…
|
Improper input validation in SAP NetWeaver Internet Communication Manager (update provided in KRNL32NUC & KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT KRNL64NUC & KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49…
|
CWE-20
Improper Input Validation
|
CVE-2020-6304
|
2024-11-21 14:35 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196942
|
9.1 |
CRITICAL
Network
|
bftpd_project
|
bftpd
|
An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitialized value. The daemon crashes at startup in the hidegroups_init function in d…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-6162
|
2024-11-21 14:35 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196943
|
7.6 |
HIGH
Network
|
webfactoryltd
|
minimal_coming_soon_\&_maintenance_mode
|
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availa…
|
CWE-862
Missing Authorization
|
CVE-2020-6168
|
2024-11-21 14:35 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196944
|
5.4 |
MEDIUM
Network
|
webfactoryltd
|
minimal_coming_soon_\&_maintenance_mode
|
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-6166
|
2024-11-21 14:35 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196945
|
8.8 |
HIGH
Network
|
webfactoryltd
|
minimal_coming_soon_\&_maintenance_mode
|
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote …
|
CWE-352
Origin Validation Error
|
CVE-2020-6167
|
2024-11-21 14:35 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196946
|
9.8 |
CRITICAL
Network
|
genexis
|
platinum-4410_firmware
|
An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the HTML source code of the cgi-bin/index2.asp URI.
|
CWE-200 CWE-306
Information Exposure Missing Authentication for Critical Function
|
CVE-2020-6170
|
2024-11-21 14:35 |
2020-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196947
|
6.1 |
MEDIUM
Network
|
mediawiki
|
mediawiki
|
The WikibaseMediaInfo extension 1.35 for MediaWiki allows XSS because of improper template syntax within the PropertySuggestionsWidget template (in the templates/search/PropertySuggestionsWidget.must…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6163
|
2024-11-21 14:35 |
2020-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196948
|
7.5 |
HIGH
Local
|
insyde siemens
|
insydeh2o ruggedcom_ape1808_firmware simatic_field_pg_m6_firmware simatic_ipc127e_firmware simatic_ipc227g_firmware simatic_ipc277g_firmware simatic_itp1000_firmware simatic_ipc4…
|
A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariab…
|
NVD-CWE-noinfo
|
CVE-2020-5953
|
2024-11-21 14:34 |
2022-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196949
|
7.5 |
HIGH
Network
|
insyde
|
insydeh2o
|
An issue was discovered in SdLegacySmm in Insyde InsydeH2O with kernel 5.1 before 05.15.11, 5.2 before 05.25.11, 5.3 before 05.34.11, and 5.4 before 05.42.11. The software SMI handler allows untruste…
|
CWE-20
Improper Input Validation
|
CVE-2020-5956
|
2024-11-21 14:34 |
2022-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196950
|
9.8 |
CRITICAL
Network
|
insyde
|
insydeh2o_uefi_bios
|
An issue was discovered in Int15MicrocodeSmm in Insyde InsydeH2O before 2021-10-14 on Intel client chipsets. A caller may be able to escalate privileges.
|
NVD-CWE-noinfo
|
CVE-2020-5955
|
2024-11-21 14:34 |
2021-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|