|
210561
|
7.8 |
HIGH
Local
|
thomsonstb philips
|
tht741fta_firmware dtr3502bfta_dvb-t2_firmware
|
THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes have their TELNET service hardcoded to start on boot, which allows an attacker on the local network to achieve root access v…
|
NVD-CWE-noinfo
|
CVE-2020-11618
|
2024-11-21 13:58 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210562
|
5.9 |
MEDIUM
Network
|
thomsonstb philips
|
tht741fta_firmware dtr3502bfta_dvb-t2_firmware
|
The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to mo…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-11617
|
2024-11-21 13:58 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210563
|
7.5 |
HIGH
Network
|
mitel
|
micollab_audio\ _web_\&_video_conferencing
|
An Authentication Bypass vulnerability in the Published Area of the web conferencing component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an unauthenticated attacker to gai…
|
NVD-CWE-noinfo
|
CVE-2020-11797
|
2024-11-21 13:58 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210564
|
7.5 |
HIGH
Network
|
woocommerce
|
nab_transact
|
An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrar…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-11497
|
2024-11-21 13:58 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210565
|
7.5 |
HIGH
Network
|
microfocus
|
arcsight_management_center
|
Denial of service vulnerability on Micro Focus ArcSight Management Center. Affecting all versions prior to version 2.9.5. The vulnerability could cause the server to become unavailable, causing a den…
|
NVD-CWE-noinfo
|
CVE-2020-11848
|
2024-11-21 13:58 |
2020-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210566
|
6.7 |
MEDIUM
Local
|
spirent
|
avalanche testcenter
|
An issue was discovered on Spirent TestCenter and Avalanche appliance admin interface firmware. An attacker, who already has access to an SSH restricted shell, can achieve root access via shell metac…
|
CWE-78
OS Command
|
CVE-2020-11733
|
2024-11-21 13:58 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210567
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_adselfservice_plus
|
An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privileges associated with a Certificate dialog. This vul…
|
CWE-269
Improper Privilege Management
|
CVE-2020-11552
|
2024-11-21 13:58 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210568
|
8.8 |
HIGH
Network
|
microfocus
|
secure_messaging_gateway
|
DKIM key management page vulnerability on Micro Focus Secure Messaging Gateway (SMG). Affecting all SMG Appliance running releases prior to July 2020. The vulnerability could allow a logged in user w…
|
CWE-78
OS Command
|
CVE-2020-11852
|
2024-11-21 13:58 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210569
|
5.5 |
MEDIUM
Local
|
canonical
|
whoopsie
|
In whoopsie, parse_report() from whoopsie.c allows a local attacker to cause a denial of service via a crafted file. The DoS is caused by resource exhaustion due to a memory leak. Fixed in 0.2.52.5ub…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-11937
|
2024-11-21 13:58 |
2020-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210570
|
6.1 |
MEDIUM
Network
|
plesk
|
onyx
|
A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11584
|
2024-11-21 13:58 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|