|
210631
|
8.8 |
HIGH
Network
|
vivotek
|
cc9381-hv_firmware fd9360-h_firmware fd9368-htv_firmware fd9380-h_firmware fd9388-htv_firmware ib9360-h_firmware ib9368-ht_firmware ib9380-h_firmware ib9388-ht_firmware it9…
|
VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execute a script (with resultant execution of OS commands). For …
|
CWE-78
OS Command
|
CVE-2020-11950
|
2024-11-21 13:58 |
2020-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210632
|
6.5 |
MEDIUM
Network
|
vivotek
|
cc9381-hv_firmware fd9360-h_firmware fd9368-htv_firmware fd9380-h_firmware fd9388-htv_firmware ib9360-h_firmware ib9368-ht_firmware ib9380-h_firmware ib9388-ht_firmware it9…
|
testserver.cgi of the web service on VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to obtain arbitrary files from a camera's…
|
NVD-CWE-noinfo
|
CVE-2020-11949
|
2024-11-21 13:58 |
2020-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210633
|
9.8 |
CRITICAL
Network
|
panasonic
|
eluga_ray_530_firmware eluga_ray_600_firmware p110_firmware eluga_z1_pro_firmware eluga_x1_firmware eluga_x1_pro_firmware
|
Panasonic P110, Eluga Z1 Pro, Eluga X1, and Eluga X1 Pro devices through 2020-04-10 have Insecure Permissions. NOTE: the vendor states that all affected products are at "End-of-software-support."
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-11716
|
2024-11-21 13:58 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210634
|
8.8 |
HIGH
Network
|
ifax avantfax
|
hylafax avantfax
|
sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection.
|
CWE-78
OS Command
|
CVE-2020-11766
|
2024-11-21 13:58 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210635
|
9.8 |
CRITICAL
Network
|
panasonic
|
p99_firmware
|
Panasonic P99 devices through 2020-04-10 have Incorrect Access Control. NOTE: the vendor states that all affected products are at "End-of-software-support."
|
NVD-CWE-noinfo
|
CVE-2020-11715
|
2024-11-21 13:58 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210636
|
7.8 |
HIGH
Local
|
sourcefabric
|
newscoop
|
Because of Unrestricted Upload of a File with a Dangerous Type, Sourcefabric Newscoop 4.4.7 allows an authenticated user to execute arbitrary PHP code (and sometimes terminal commands) on a server by…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-11807
|
2024-11-21 13:58 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210637
|
6.1 |
MEDIUM
Network
|
microfocus
|
service_manager
|
Cross Site Scripting vulnerability in Micro Focus Service Manager product. Affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. The vulnerability could be exploited to allow remote attackers …
|
CWE-79
Cross-site Scripting
|
CVE-2020-11845
|
2024-11-21 13:58 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210638
|
6.5 |
MEDIUM
Adjacent
|
netgear
|
rbs50y_firmware srr60_firmware srs60_firmware
|
An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 …
|
NVD-CWE-noinfo
|
CVE-2020-11550
|
2024-11-21 13:58 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210639
|
8.8 |
HIGH
Adjacent
|
netgear
|
rbs50y_firmware srr60_firmware srs60_firmware
|
An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-11549
|
2024-11-21 13:58 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210640
|
8.8 |
HIGH
Adjacent
|
netgear
|
rbs50y_firmware srr60_firmware srs60_firmware
|
An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 …
|
CWE-287 CWE-330
Improper Authentication Use of Insufficiently Random Values
|
CVE-2020-11551
|
2024-11-21 13:58 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|