|
210381
|
7.5 |
HIGH
Network
|
zohocorp
|
manageengine_opmanager
|
Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.
|
CWE-22
Path Traversal
|
CVE-2020-12116
|
2024-11-21 13:59 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210382
|
7.8 |
HIGH
Local
|
solarwinds
|
managed_service_provider_patch_management_engine
|
An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Monitoring Agent. There are insecure file permissions for %PROGRAMDATA%\SolarWinds …
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-12608
|
2024-11-21 13:59 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210383
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet.
|
CWE-22
Path Traversal
|
CVE-2020-12448
|
2024-11-21 13:59 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210384
|
6.5 |
MEDIUM
Network
|
gnu debian fedoraproject opensuse canonical
|
mailman debian_linux fedora leap backports_sle ubuntu_linux
|
/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
|
CWE-74
Injection
|
CVE-2020-12108
|
2024-11-21 13:59 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210385
|
7.8 |
HIGH
Local
|
avira
|
software_updater
|
An elevation of privilege vulnerability exists in Avira Software Updater before 2.0.6.27476 due to improperly handling file hard links. This allows local users to obtain take control of arbitrary fil…
|
NVD-CWE-noinfo
|
CVE-2020-12463
|
2024-11-21 13:59 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210386
|
5.3 |
MEDIUM
Network
|
grin
|
grin
|
Grin before 3.1.0 allows attackers to adversely affect availability of data on a Mimblewimble blockchain.
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2020-12439
|
2024-11-21 13:59 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210387
|
4.9 |
MEDIUM
Network
|
silver-peak
|
unity_edgeconnect_for_google_cloud_platform unity_edgeconnect_for_azure unity_edgeconnect_for_amazon_web_services unity_orchestrator vx-500_firmware vx-1000_firmware vx-2000_firmwar…
|
The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeConnect to an untruste…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-12144
|
2024-11-21 13:59 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210388
|
4.9 |
MEDIUM
Network
|
silver-peak
|
unity_edgeconnect_for_google_cloud_platform unity_edgeconnect_for_azure unity_edgeconnect_for_amazon_web_services unity_orchestrator vx-500_firmware vx-1000_firmware vx-2000_firmwar…
|
The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-12143
|
2024-11-21 13:59 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210389
|
4.9 |
MEDIUM
Network
|
silver-peak
|
unity_edgeconnect_for_google_cloud_platform unity_edgeconnect_for_azure unity_edgeconnect_for_amazon_web_services unity_orchestrator vx-500_firmware vx-1000_firmware vx-2000_firmwar…
|
1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could …
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-12142
|
2024-11-21 13:59 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210390
|
8.8 |
HIGH
Network
|
internet-formation
|
wp-advanced-search
|
The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands withou…
|
CWE-89
SQL Injection
|
CVE-2020-12104
|
2024-11-21 13:59 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|