|
197441
|
5.4 |
MEDIUM
Network
|
riken
|
xoonips
|
Reflected cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5662
|
2024-11-21 14:34 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197442
|
8.8 |
HIGH
Network
|
riken
|
xoonips
|
SQL injection vulnerability in the XooNIps 3.49 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2020-5659
|
2024-11-21 14:34 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197443
|
7.5 |
HIGH
Network
|
mitsubishielectric
|
melsec_iq-r00_firmware melsec_iq-r01_firmware melsec_iq-r02_firmware melsec_iq-r04_firmware melsec_iq-r16_firmware melsec_iq-r08_firmware melsec_iq-r32_firmware melsec_iq-r120_fi…
|
Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '05' to '19' and R04/08/16/32/120(EN)CPU Firmware versions from '35' to '51') al…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-5666
|
2024-11-21 14:34 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197444
|
7.8 |
HIGH
Local
|
nagios
|
nagios_xi
|
Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of files, resulting in low-privileged users being able to write to…
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-5796
|
2024-11-21 14:34 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197445
|
7.5 |
HIGH
Network
|
valvesoftware
|
game_networking_sockets
|
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConnectionTransportUDPBase::Received_Data(), leading to an exception thrown from li…
|
NVD-CWE-noinfo
|
CVE-2020-6019
|
2024-11-21 14:34 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197446
|
7.8 |
HIGH
Local
|
nvidia
|
geforce_now
|
NVIDIA GeForce NOW application software on Windows, all versions prior to 2.0.25.119, contains a vulnerability in its open-source software dependency in which the OpenSSL library is vulnerable to bin…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-5992
|
2024-11-21 14:34 |
2020-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197447
|
9.8 |
CRITICAL
Network
|
vmware
|
pivotal_scheduler
|
Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a non-TLS connection. This also depended on the configuration of the MySQL server…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-5426
|
2024-11-21 14:34 |
2020-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197448
|
6.9 |
MEDIUM
Physics
|
dell
|
inspiron_15_7579_firmware
|
Dell Inspiron 15 7579 2-in-1 BIOS versions prior to 1.31.0 contain an Improper SMM communication buffer verification vulnerability. A local authenticated malicious user may potentially exploit this v…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-5388
|
2024-11-21 14:34 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197449
|
7.8 |
HIGH
Local
|
tenable
|
nessus_network_monitor
|
A vulnerability in Nessus Network Monitor versions 5.11.0, 5.11.1, and 5.12.0 for Windows could allow an authenticated local attacker to execute arbitrary code by copying user-supplied files to a spe…
|
NVD-CWE-noinfo
|
CVE-2020-5794
|
2024-11-21 14:34 |
2020-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197450
|
6.2 |
MEDIUM
Physics
|
tp-link
|
archer_a7_firmware
|
UNIX Symbolic Link (Symlink) Following in TP-Link Archer A7(US)_V5_200721 allows an authenticated admin user, with physical access and network access, to execute arbitrary code after plugging a craft…
|
CWE-59
Link Following
|
CVE-2020-5795
|
2024-11-21 14:34 |
2020-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|