|
210981
|
9.8 |
CRITICAL
Network
|
gpac
|
gpac
|
An issue was discovered in libgpac.a in GPAC 0.8.0, as demonstrated by MP4Box. audio_sample_entry_Read in isomedia/box_code_base.c does not properly decide when to make gf_isom_box_del calls. This le…
|
CWE-416
Use After Free
|
CVE-2020-11558
|
2024-11-21 13:58 |
2020-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210982
|
9.8 |
CRITICAL
Network
|
search_meter_project
|
search_meter
|
The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-11548
|
2024-11-21 13:58 |
2020-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210983
|
5.3 |
MEDIUM
Network
|
paessler
|
prtg_network_monitor
|
PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal stat…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-11547
|
2024-11-21 13:58 |
2020-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210984
|
9.8 |
CRITICAL
Network
|
3xlogic
|
infinias_eidc32_firmware infinias_eidc32_web
|
3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the <KEY>MYKEY</KEY> substring.
|
CWE-287 CWE-319
Improper Authentication Cleartext Transmission of Sensitive Information
|
CVE-2020-11542
|
2024-11-21 13:58 |
2020-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210985
|
5.5 |
MEDIUM
Local
|
ivanti
|
workspace_control
|
Ivanti Workspace Control before 10.4.30.0, when SCCM integration is enabled, allows local users to obtain sensitive information (keying material).
|
NVD-CWE-noinfo
|
CVE-2020-11533
|
2024-11-21 13:58 |
2020-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210986
|
6.1 |
MEDIUM
Network
|
getgrav
|
grav
|
Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.
|
CWE-601
Open Redirect
|
CVE-2020-11529
|
2024-11-21 13:58 |
2020-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210987
|
7.5 |
HIGH
Network
|
bit2spr_project
|
bit2spr
|
bit2spr 1992-06-07 has a stack-based buffer overflow (129-byte write) in conv_bitmap in bit2spr.c via a long line in a bitmap file.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-11528
|
2024-11-21 13:58 |
2020-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210988
|
7.5 |
HIGH
Network
|
zohocorp
|
manageengine_opmanager
|
In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
|
NVD-CWE-noinfo
|
CVE-2020-11527
|
2024-11-21 13:58 |
2020-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210989
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_adselfservice_plus
|
Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-11518
|
2024-11-21 13:58 |
2020-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210990
|
7.4 |
HIGH
Network
|
gnu debian opensuse canonical fedoraproject
|
gnutls debian_linux leap ubuntu_linux fedora
|
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' by…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-11501
|
2024-11-21 13:58 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|