|
210241
|
6.1 |
MEDIUM
Network
|
tiny
|
tinymce
|
A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configured in classic editing mode.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12648
|
2024-11-21 13:59 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210242
|
8.2 |
HIGH
Local
|
intel
|
s2600wftr_firmware s2600wf0r_firmware s2600wfqr_firmware s2600bpsr_firmware s2600bpbr_firmware s2600bpqr_firmware s2600stqr_firmware s2600stbr_firmware
|
Improper initialization in BIOS firmware for Intel(R) Server Board Families S2600ST, S2600BP and S2600WF may allow a privileged user to potentially enable escalation of privilege via local access.
|
CWE-665
Improper Initialization
|
CVE-2020-12301
|
2024-11-21 13:59 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210243
|
8.2 |
HIGH
Local
|
intel
|
s2600stqr_firmware s2600stbr_firmware s2600bpsr_firmware s2600bpbr_firmware s2600bpqr_firmware s2600wftr_firmware s2600wf0r_firmware s2600wfqr_firmware
|
Improper input validation in BIOS firmware for Intel(R) Server Board Families S2600ST, S2600BP and S2600WF may allow a privileged user to potentially enable escalation of privilege via local access.
|
CWE-20
Improper Input Validation
|
CVE-2020-12299
|
2024-11-21 13:59 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210244
|
8.2 |
HIGH
Local
|
intel
|
s2600cw2_firmware s2600cw2s_firmware s2600cwt_firmware s2600cwts_firmware s2600cw2r_firmware s2600cw2sr_firmware s2600cwtr_firmware s2600cwtsr_firmware s2600kp_firmware s26…
|
Uninitialized pointer in BIOS firmware for Intel(R) Server Board Families S2600CW, S2600KP, S2600TP, and S2600WT may allow a privileged user to potentially enable escalation of privilege via local ac…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2020-12300
|
2024-11-21 13:59 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210245
|
7.8 |
HIGH
Local
|
intel
|
distribution_of_openvino_toolkit
|
Incorrect permissions in the Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2020.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-12287
|
2024-11-21 13:59 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210246
|
9.8 |
CRITICAL
Network
|
stengg
|
vpncrypt_m10_firmware
|
The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows command injection via a text field, which allow full control over this module's Operating System.
|
CWE-78
OS Command
|
CVE-2020-12107
|
2024-11-21 13:59 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210247
|
9.8 |
CRITICAL
Network
|
stengg
|
vpncrypt_m10_firmware
|
The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative functions such as, changing credentials of the Admini…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-12106
|
2024-11-21 13:59 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210248
|
7.5 |
HIGH
Network
|
dovecot debian fedoraproject canonical
|
dovecot debian_linux fedora ubuntu_linux
|
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply ne…
|
CWE-674
Uncontrolled Recursion
|
CVE-2020-12100
|
2024-11-21 13:59 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210249
|
7.5 |
HIGH
Network
|
apache
|
wicket fortress
|
By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually r…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2020-11976
|
2024-11-21 13:59 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210250
|
7.5 |
HIGH
Network
|
apache netapp canonical opensuse debian fedoraproject oracle
|
http_server clustered_data_ontap ubuntu_linux leap debian_linux fedora instantis_enterprisetrack hyperion_infrastructure_technology enterprise_manager_ops_center communicat…
|
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing con…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-11993
|
2024-11-21 13:59 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|