|
209941
|
9.8 |
CRITICAL
Network
|
ivanti
|
dsm_netinst
|
Unsafe storage of AD credentials in Ivanti DSM netinst 5.1 due to a static, hard-coded encryption key.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-13793
|
2024-11-21 14:01 |
2020-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209942
|
8.8 |
HIGH
Network
|
zyxel
|
nas326_firmware nas520_firmware nas540_firmware nas542_firmware
|
Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can be used for a TELNET session as root. This affects…
|
CWE-287
Improper Authentication
|
CVE-2020-13365
|
2024-11-21 14:01 |
2020-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209943
|
8.8 |
HIGH
Network
|
zyxel
|
nas326_firmware nas520_firmware nas540_firmware nas542_firmware
|
A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, …
|
NVD-CWE-noinfo
|
CVE-2020-13364
|
2024-11-21 14:01 |
2020-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209944
|
8.8 |
HIGH
Network
|
quadra-informatique
|
atos\/sips
|
The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection.
|
CWE-78
OS Command
|
CVE-2020-13404
|
2024-11-21 14:01 |
2020-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209945
|
6.1 |
MEDIUM
Network
|
extremenetworks
|
extreme_management_center
|
Extreme EAC Appliance 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13819
|
2024-11-21 14:01 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209946
|
7.1 |
HIGH
Local
|
softperfect
|
ram_disk
|
An exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can allow an unprivileged user to delete any file …
|
NVD-CWE-noinfo
|
CVE-2020-13522
|
2024-11-21 14:01 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209947
|
3.3 |
LOW
Local
|
softperfect
|
ram_disk
|
An exploitable information disclosure vulnerability exists in SoftPerfect’s RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can cause the disclosure of sensitive informati…
|
CWE-862
Missing Authorization
|
CVE-2020-13523
|
2024-11-21 14:01 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209948
|
6.1 |
MEDIUM
Network
|
extremenetworks
|
extreme_management_center
|
Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13820
|
2024-11-21 14:01 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209949
|
8.8 |
HIGH
Network
|
teamviewer
|
teamviewer
|
TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10:…
|
CWE-88
Argument Injection
|
CVE-2020-13699
|
2024-11-21 14:01 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209950
|
7.5 |
HIGH
Network
|
microweber
|
microweber
|
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-13405
|
2024-11-21 14:01 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|