|
209871
|
4.4 |
MEDIUM
Local
|
philips
|
clearvue_850_firmware clearvue_350_firmware cx50_firmware affiniti_70_firmware affiniti_50_firmware epiq_7_firmware sparq_firmware xperius_firmware
|
In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti Versions VM5.0 and prior, Ultrasound Sparq Version 3.0.2 and prior and Ultrasou…
|
CWE-287
Improper Authentication
|
CVE-2020-14477
|
2024-11-21 14:03 |
2020-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209872
|
9.8 |
CRITICAL
Network
|
draytek
|
vigor300b_firmware vigor2960_firmware vigor3900_firmware
|
Stack-based buffer overflow vulnerability in Vigor3900, Vigor2960, and Vigor300B with firmware before 1.5.1.1.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-14473
|
2024-11-21 14:03 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209873
|
9.8 |
CRITICAL
Network
|
draytek
|
vigor300b_firmware vigor2960_firmware vigor3900_firmware
|
On Draytek Vigor3900, Vigor2960, and Vigor 300B devices before 1.5.1.1, there are some command-injection vulnerabilities in the mainfunction.cgi file.
|
CWE-77
Command Injection
|
CVE-2020-14472
|
2024-11-21 14:03 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209874
|
8.6 |
HIGH
Network
|
zyxel
|
wap6806_firmware
|
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
|
CWE-22
Path Traversal
|
CVE-2020-14461
|
2024-11-21 14:03 |
2020-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209875
|
6.1 |
MEDIUM
Network
|
dolibarr
|
dolibarr_erp\/crm
|
A reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.3 allows remote attackers to inject arbitrary web script or HTML into public/notice.php (related to transphrase and transkey).
|
CWE-79
Cross-site Scripting
|
CVE-2020-14475
|
2024-11-21 14:03 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209876
|
6.5 |
MEDIUM
Network
|
octopus
|
octopus_deploy
|
In Octopus Deploy 2018.8.0 through 2019.x before 2019.12.2, an authenticated user with could trigger a deployment that leaks the Helm Chart repository password.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-14470
|
2024-11-21 14:03 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209877
|
6.5 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 5.19.0, 5.18.1, 5.17.3, 5.16.5, and 5.9.8. Creation of a trusted OAuth application does not always require admin privileges, aka MMSA-2020-0001.
|
NVD-CWE-noinfo
|
CVE-2020-14460
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209878
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 5.19.0. Attackers can rename a channel and cause a collision with a direct message, aka MMSA-2020-0002.
|
CWE-20
Improper Input Validation
|
CVE-2020-14459
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209879
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 5.19.0. Attackers can discover private channels via the "get channel by name" API, aka MMSA-2020-0004.
|
NVD-CWE-noinfo
|
CVE-2020-14458
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209880
|
5.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 5.20.0. Non-members can receive broadcasted team details via the update_team WebSocket event, aka MMSA-2020-0012.
|
NVD-CWE-noinfo
|
CVE-2020-14457
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|