|
196781
|
8.8 |
HIGH
Network
|
kinetica
|
kinetica
|
The Admin web application in Kinetica 7.0.9.2.20191118151947 does not properly sanitise the input for the function getLogs. This lack of sanitisation could be exploited to allow an authenticated atta…
|
CWE-78
OS Command
|
CVE-2020-8429
|
2024-11-21 14:38 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196782
|
5.4 |
MEDIUM
Network
|
piwigo
|
piwigo
|
Piwigo 2.10.1 is affected by stored XSS via the Group Name Field to the group_list page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8089
|
2024-11-21 14:38 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196783
|
7.8 |
HIGH
Local
|
ui
|
edgeswitch
|
A privilege escalation in the EdgeSwitch prior to version 1.7.1, an CGI script don't fully sanitize the user input resulting in local commands execution, allowing an operator user (Privilege-1) to es…
|
CWE-78
OS Command
|
CVE-2020-8126
|
2024-11-21 14:38 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196784
|
7.8 |
HIGH
Local
|
opservices
|
opmon
|
An issue was discovered in OpServices OpMon 9.3.2. Starting from the apache user account, it is possible to perform privilege escalation through the lack of correct configuration in the server's sudo…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-7954
|
2024-11-21 14:38 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196785
|
7.5 |
HIGH
Network
|
opservices
|
opmon
|
An issue was discovered in OpServices OpMon 9.3.2. Without authentication, it is possible to read server files (e.g., /etc/passwd) due to the use of the nmap -iL (aka input file) option.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-7953
|
2024-11-21 14:38 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196786
|
7.5 |
HIGH
Network
|
percona
|
monitoring_and_management
|
pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-7920
|
2024-11-21 14:38 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196787
|
7.5 |
HIGH
Network
|
rogersmedia
|
citytv_video
|
The Citytv Video application 4.08.0 for Android and 3.35 for iOS sends Unencrypted Analytics.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-8507
|
2024-11-21 14:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196788
|
5.3 |
MEDIUM
Network
|
corusent
|
global_tv
|
The Global TV application 2.3.2 for Android and 4.7.5 for iOS sends Unencrypted Analytics.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-8506
|
2024-11-21 14:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196789
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.
|
NVD-CWE-noinfo
|
CVE-2020-7978
|
2024-11-21 14:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196790
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-7977
|
2024-11-21 14:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|