|
210181
|
8.8 |
HIGH
Adjacent
|
dlink
|
dir-842_firmware
|
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-842 3.13B05 routers. Authentication is not required to exploit this vulnerability…
|
-
|
CVE-2020-15632
|
2024-11-21 14:05 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210182
|
8.0 |
HIGH
Adjacent
|
dlink
|
dap-1860_firmware
|
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 1.04B03_HOTFIX WiFi extenders. Although authentication is required to explo…
|
-
|
CVE-2020-15631
|
2024-11-21 14:05 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210183
|
9.8 |
CRITICAL
Network
|
inneo
|
startup_tools
|
An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP port 85) includes user input into a filesystem acc…
|
CWE-22
Path Traversal
|
CVE-2020-15492
|
2024-11-21 14:05 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210184
|
9.8 |
CRITICAL
Network
|
raspberrytorte
|
raspberrytortoise
|
The WebControl in RaspberryTortoise through 2012-10-28 is vulnerable to remote code execution via shell metacharacters in a URI. The file nodejs/raspberryTortoise.js has no validation on the paramete…
|
CWE-78
OS Command
|
CVE-2020-15477
|
2024-11-21 14:05 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210185
|
9.8 |
CRITICAL
Network
|
devspace
|
devspace
|
The UI in DevSpace 4.13.0 allows web sites to execute actions on pods (on behalf of a victim) because of a lack of authentication for the WebSocket protocol. This leads to remote code execution.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-15391
|
2024-11-21 14:05 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210186
|
6.1 |
MEDIUM
Network
|
jalios
|
jcms
|
jcore/portal/ajaxPortal.jsp in Jalios JCMS 10.0.2 build-20200224104759 allows XSS via the types parameter. Note: It is asserted that this vulnerability is not present in the standard installation of …
|
CWE-79
Cross-site Scripting
|
CVE-2020-15497
|
2024-11-21 14:05 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210187
|
5.9 |
MEDIUM
Network
|
golang cloudfoundry debian opensuse fedoraproject
|
go cf-deployment routing-release debian_linux leap fedora
|
Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the…
|
CWE-362
Race Condition
|
CVE-2020-15586
|
2024-11-21 14:05 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210188
|
7.5 |
HIGH
Network
|
trendmicro
|
antivirus\+_2020 internet_security_2020 maximum_security_2020 premium_security_2020
|
An invalid memory read vulnerability in a Trend Micro Secuity 2020 (v16.0.0.1302 and below) consumer family of products' driver could allow an attacker to manipulate the specific driver to do a syste…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-15603
|
2024-11-21 14:05 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210189
|
5.6 |
MEDIUM
Network
|
ajv.js
|
ajv
|
An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype polluti…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-15366
|
2024-11-21 14:05 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210190
|
7.8 |
HIGH
Local
|
trendmicro
|
antivirus\+_2020 internet_security_2020 maximum_security_2020 premium_security_2020
|
An untrusted search path remote code execution (RCE) vulnerability in the Trend Micro Secuity 2020 (v16.0.0.1146 and below) consumer family of products could allow an attacker to run arbitrary code o…
|
CWE-426
Untrusted Search Path
|
CVE-2020-15602
|
2024-11-21 14:05 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|