|
197201
|
7.5 |
HIGH
Network
|
uap-core_project
|
uap-core
|
uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regexes are vulnerable to regular expression denial of service (REDoS) due to overla…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2020-5243
|
2024-11-21 14:33 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197202
|
8.8 |
HIGH
Network
|
openhab
|
openhab
|
openHAB before 2.5.2 allow a remote attacker to use REST calls to install the EXEC binding or EXEC transformation service and execute arbitrary commands on the system with the privileges of the user …
|
CWE-863
Incorrect Authorization
|
CVE-2020-5242
|
2024-11-21 14:33 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197203
|
5.3 |
MEDIUM
Physics
|
dell
|
chengming_3980_firmware g3_3579_firmware g3_3590_firmware g3_3779_firmware g5_5587_firmware g5_5590_firmware g7_7588_firmware g7_7590_firmware g7_7790_firmware embedded_box…
|
Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu. An attacker with phy…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-5326
|
2024-11-21 14:33 |
2020-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197204
|
4.4 |
MEDIUM
Local
|
dell
|
g3_3579_firmware g3_3779_firmware g3_15_3590_firmware g5_15_5590_firmware g5_5090_firmware g5_5587_firmware g7_15_7590_firmware g7_17_7790_firmware g7_7588_firmware inspiro…
|
Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being ex…
|
CWE-59
Link Following
|
CVE-2020-5324
|
2024-11-21 14:33 |
2020-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197205
|
8.8 |
HIGH
Network
|
mailu
|
mailu
|
In Mailu before version 1.7, an authenticated user can exploit a vulnerability in Mailu fetchmail script and gain full access to a Mailu instance. Mailu servers that have open registration or untrust…
|
NVD-CWE-noinfo
|
CVE-2020-5239
|
2024-11-21 14:33 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197206
|
5.4 |
MEDIUM
Network
|
matestack
|
ui-core
|
matestack-ui-core (RubyGem) before 0.7.4 is vulnerable to XSS/Script injection. This vulnerability is patched in version 0.7.4.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5241
|
2024-11-21 14:33 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197207
|
7.5 |
HIGH
Network
|
dell
|
emc_unity_operating_environment emc_unityvsa_operating_environment emc_unity_xt_operating_environment
|
Dell EMC Unity, Dell EMC Unity XT, and Dell EMC UnityVSA versions prior to 5.0.2.0.5.009 contain a Denial of Service vulnerability on NAS Server SSH implementation that is used to provide SFTP servic…
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-5319
|
2024-11-21 14:33 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197208
|
7.5 |
HIGH
Network
|
dell
|
emc_isilon_onefs
|
Dell EMC Isilon OneFS versions 8.1.2, 8.1.0.4, 8.1.0.3, and 8.0.0.7 contain a vulnerability in some configurations. An attacker may exploit this vulnerability to gain access to restricted files. The …
|
CWE-863
Incorrect Authorization
|
CVE-2020-5318
|
2024-11-21 14:33 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197209
|
4.8 |
MEDIUM
Network
|
dell
|
emc_elastic_cloud_storage
|
Dell EMC ECS versions prior to 3.4.0.1 contain an XSS vulnerability. A remote authenticated malicious user could exploit this vulnerability to store malicious HTML or JavaScript code in a trusted app…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5317
|
2024-11-21 14:33 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197210
|
8.8 |
HIGH
Network
|
1up
|
oneupuploaderbundle
|
Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attackers to upload, copy, and modify files on the filesystem (potentially leading to…
|
CWE-22
Path Traversal
|
CVE-2020-5237
|
2024-11-21 14:33 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|