|
196821
|
9.8 |
CRITICAL
Network
|
draytek
|
vigor2960_firmware vigor300b_firmware vigor3900_firmware
|
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacter…
|
CWE-78
OS Command
|
CVE-2020-8515
|
2024-11-21 14:38 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196822
|
6.1 |
MEDIUM
Network
|
icewarp
|
icewarp_server
|
In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8512
|
2024-11-21 14:38 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196823
|
6.5 |
MEDIUM
Network
|
arox
|
school_management_software_php\/mysql
|
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user.
|
CWE-352
Origin Validation Error
|
CVE-2020-8505
|
2024-11-21 14:38 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196824
|
6.5 |
MEDIUM
Network
|
arox
|
school_management_software_php\/mysql
|
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrative user.
|
CWE-352
Origin Validation Error
|
CVE-2020-8504
|
2024-11-21 14:38 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196825
|
6.5 |
MEDIUM
Network
|
biscom
|
secure_file_transfer
|
Biscom Secure File Transfer (SFT) 5.0.1050 through 5.1.1067 and 6.0.1000 through 6.0.1003 allows Insecure Direct Object Reference (IDOR) by an authenticated sender because of an error in a file-uploa…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-8503
|
2024-11-21 14:38 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196826
|
4.3 |
MEDIUM
Network
|
zohocorp
|
manageengine_remote_access_plus
|
An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450. A user with the Guest role can extract the collection of all defined c…
|
NVD-CWE-noinfo
|
CVE-2020-8422
|
2024-11-21 14:38 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196827
|
9.8 |
CRITICAL
Network
|
simplejobscript
|
simplejobscript
|
controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by uploading a PHP script as a resume.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-8440
|
2024-11-21 14:38 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196828
|
9.8 |
CRITICAL
Network
|
hashicorp
|
nomad
|
HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susceptible to privilege escalation. Fixed in 0.10.3.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-7956
|
2024-11-21 14:38 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196829
|
5.3 |
MEDIUM
Network
|
hashicorp
|
consul
|
HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended information disclosure. Fixed in 1.6.3.
|
CWE-863
Incorrect Authorization
|
CVE-2020-7955
|
2024-11-21 14:38 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196830
|
7.5 |
HIGH
Network
|
jetbrains
|
intellij_idea
|
In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over the network. This issue was fixed in 2019.3.
|
NVD-CWE-noinfo
|
CVE-2020-7914
|
2024-11-21 14:38 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|