|
197681
|
6.5 |
MEDIUM
Network
|
vmware
|
spring_cloud_netflix
|
Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make reques…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2020-5412
|
2024-11-21 14:34 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197682
|
9.8 |
CRITICAL
Network
|
yokogawa
|
centum_cs_3000_firmware centum_vp_firmware b\/m9000cs_firmware b\/m9000vp_firmware
|
Directory traversal vulnerability in CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.0…
|
CWE-22
Path Traversal
|
CVE-2020-5609
|
2024-11-21 14:34 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197683
|
9.8 |
CRITICAL
Network
|
yokogawa
|
centum_cs_3000_firmware centum_vp_firmware b\/m9000cs_firmware b\/m9000vp_firmware
|
CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, and B/M9000 VP R6.0…
|
CWE-287
Improper Authentication
|
CVE-2020-5608
|
2024-11-21 14:34 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197684
|
7.4 |
HIGH
Local
|
checkpoint
|
zonealarm_anti-ransomware
|
ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked cont…
|
CWE-59
Link Following
|
CVE-2020-6012
|
2024-11-21 14:34 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197685
|
7.8 |
HIGH
Local
|
skygroup
|
skysea_client_view
|
Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unauthorized privileges and modify/obtain sensitive information or perform unintende…
|
CWE-269
Improper Privilege Management
|
CVE-2020-5617
|
2024-11-21 14:34 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197686
|
9.8 |
CRITICAL
Network
|
calendar02_project calendar01_project link01_project calendarform01_project gallery01_project telop01_project pkobo-vote01_project pkobo-news01_project
|
calendar02 calendar01 link01 calendarform01 gallery01 telop01 pkobo-vote01 pkobo-news01
|
[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News0…
|
CWE-287
Improper Authentication
|
CVE-2020-5616
|
2024-11-21 14:34 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197687
|
8.8 |
HIGH
Network
|
calendar02_project calendar01_project
|
calendar02 calendar01
|
Cross-site request forgery (CSRF) vulnerability in [Calendar01] free edition ver1.0.0 and [Calendar02] free edition ver1.0.0 allows remote attackers to hijack the authentication of administrators via…
|
CWE-352
Origin Validation Error
|
CVE-2020-5615
|
2024-11-21 14:34 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197688
|
8.8 |
HIGH
Network
|
teltonika-networks
|
trb245_firmware
|
Improper Access Control in Teltonika firmware TRB2_R_00.02.04.01 allows a low privileged user to perform unauthorized write operations.
|
CWE-269
Improper Privilege Management
|
CVE-2020-5773
|
2024-11-21 14:34 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197689
|
7.5 |
HIGH
Network
|
teltonika-networks
|
trb245_firmware
|
Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious package file.
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-5772
|
2024-11-21 14:34 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197690
|
7.5 |
HIGH
Network
|
teltonika-networks
|
trb245_firmware
|
Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious backup archive.
|
CWE-20
Improper Input Validation
|
CVE-2020-5771
|
2024-11-21 14:34 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|