|
196721
|
7.5 |
HIGH
Network
|
st
|
stm32f1_firmware
|
STMicroelectronics STM32F1 devices have Incorrect Access Control.
|
NVD-CWE-noinfo
|
CVE-2020-8004
|
2024-11-21 14:38 |
2020-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196722
|
9.8 |
CRITICAL
Network
|
utils-extend_project
|
utils-extend
|
Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using…
|
CWE-20
Improper Input Validation
|
CVE-2020-8147
|
2024-11-21 14:38 |
2020-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196723
|
6.1 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could trick logged-in users to open a specifically crafted…
|
CWE-601
Open Redirect
|
CVE-2020-8143
|
2024-11-21 14:38 |
2020-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196724
|
6.8 |
MEDIUM
Physics
|
revive-adserver
|
revive_adserver
|
A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144. Revive Adserver, like many other applications, requires the logged in u…
|
CWE-863
Incorrect Authorization
|
CVE-2020-8142
|
2024-11-21 14:38 |
2020-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196725
|
7.2 |
HIGH
Network
|
tp-link
|
tl-wr841n_firmware
|
A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for th…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-8423
|
2024-11-21 14:38 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196726
|
6.3 |
MEDIUM
Local
|
opensuse
|
texlive-filesystem leap
|
A Race Condition Enabling Link Following vulnerability in the cron job shipped with texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software …
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2020-8017
|
2024-11-21 14:38 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196727
|
7.0 |
HIGH
Local
|
opensuse
|
texlive-filesystem
|
A Race Condition Enabling Link Following vulnerability in the packaging of texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Developme…
|
-
|
CVE-2020-8016
|
2024-11-21 14:38 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196728
|
7.8 |
HIGH
Local
|
exim
|
exim
|
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: openSUSE Factory exi…
|
-
|
CVE-2020-8015
|
2024-11-21 14:38 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196729
|
7.8 |
HIGH
Local
|
ui
|
unifi_video
|
In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file deletion and DLL hijack vulnerabilities. The issue was fixed by adjusting the .tsE…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-8146
|
2024-11-21 14:38 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196730
|
6.5 |
MEDIUM
Network
|
ui
|
unifi_video
|
The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup” and “wizard” endpoints does not implement sufficient privilege checks. Low privileged users, belongi…
|
NVD-CWE-noinfo
|
CVE-2020-8145
|
2024-11-21 14:38 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|