|
209451
|
5.3 |
MEDIUM
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak Data.fs permissions.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-15329
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209452
|
5.3 |
MEDIUM
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-15328
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209453
|
7.5 |
HIGH
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-15327
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209454
|
5.3 |
MEDIUM
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded certificate for Ejabberd in ejabberd.pem.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-15326
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209455
|
5.3 |
MEDIUM
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-15325
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209456
|
6.5 |
MEDIUM
Network
|
broadcom
|
fabric_operating_system
|
A vulnerability in the Brocade Fabric OS before Brocade Fabric OS v9.0.1a, v8.2.3, v8.2.0_CBN4, and v7.4.2h could allow an authenticated CLI user to abuse the history command to write arbitrary conte…
|
NVD-CWE-noinfo
|
CVE-2020-15388
|
2024-11-21 14:05 |
2022-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209457
|
9.8 |
CRITICAL
Network
|
uni-stuttgart
|
frams\'_fast_file_exchange
|
fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for unauthenticated remote code execution).
|
CWE-94
Code Injection
|
CVE-2020-15591
|
2024-11-21 14:05 |
2022-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209458
|
8.8 |
HIGH
Network
|
mozilla
|
geckodriver
|
Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically prepared request, lead to remote code execution.
|
CWE-352
Origin Validation Error
|
CVE-2020-15660
|
2024-11-21 14:05 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209459
|
7.8 |
HIGH
Local
|
acronis
|
true_image
|
Acronis True Image 2019 update 1 through 2020 on macOS allows local privilege escalation due to an insecure XPC service configuration.
|
NVD-CWE-noinfo
|
CVE-2020-15495
|
2024-11-21 14:05 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209460
|
7.8 |
HIGH
Local
|
acronis
|
true_image
|
Acronis True Image for Mac before 2021 Update 4 allowed local privilege escalation due to insecure folder permissions.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-15496
|
2024-11-21 14:05 |
2021-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|