|
210401
|
5.5 |
MEDIUM
Local
|
tp-link
|
omada_controller
|
TP-Link Omada Controller Software 3.2.6 allows Directory Traversal for reading arbitrary files via com.tp_link.eap.web.portal.PortalController.getAdvertiseFile in /opt/tplink/EAPController/lib/eap-we…
|
CWE-22
Path Traversal
|
CVE-2020-12475
|
2024-11-21 13:59 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210402
|
9.8 |
CRITICAL
Network
|
tp-link
|
nc200_firmware nc210_firmware nc220_firmware nc230_firmware nc250_firmware nc260_firmware nc450_firmware
|
Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-12110
|
2024-11-21 13:59 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210403
|
5.4 |
MEDIUM
Network
|
enhancesoft
|
osticket
|
include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12629
|
2024-11-21 13:59 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210404
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
A pivot_root race condition in fs/namespace.c in the Linux kernel 4.4.x before 4.4.221, 4.9.x before 4.9.221, 4.14.x before 4.14.178, 4.19.x before 4.19.119, and 5.x before 5.3 allows local users to …
|
CWE-362
Race Condition
|
CVE-2020-12114
|
2024-11-21 13:59 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210405
|
9.8 |
CRITICAL
Network
|
janeczku
|
calibre-web
|
Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-12627
|
2024-11-21 13:59 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210406
|
6.5 |
MEDIUM
Network
|
roundcube debian
|
webmail debian_linux
|
An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.
|
CWE-352
Origin Validation Error
|
CVE-2020-12626
|
2024-11-21 13:59 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210407
|
6.1 |
MEDIUM
Network
|
roundcube debian opensuse
|
webmail debian_linux leap backports_sle
|
An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12625
|
2024-11-21 13:59 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210408
|
6.5 |
MEDIUM
Network
|
theleague
|
the_league
|
The League application before 2020-05-02 on Android sends a bearer token in an HTTP Authorization header to an arbitrary web site that hosts an external image because an OkHttp object is reused, whic…
|
CWE-459
Incomplete Cleanup
|
CVE-2020-12624
|
2024-11-21 13:59 |
2020-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210409
|
6.5 |
MEDIUM
Network
|
telegram
|
telegram telegram_desktop
|
Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Punycode in a public URL or a group chat invitation URL.
|
NVD-CWE-noinfo
|
CVE-2020-12474
|
2024-11-21 13:59 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210410
|
5.3 |
MEDIUM
Network
|
moxa
|
nport_5100a_firmware
|
Moxa Service in Moxa NPort 5150A firmware version 1.5 and earlier allows attackers to obtain sensitive configuration values via a crafted packet to UDP port 4800. NOTE: Moxa Service is an unauthentic…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-12117
|
2024-11-21 13:59 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|