|
197931
|
6.5 |
MEDIUM
Network
|
cloud_foundry
|
bosh_system_metrics_server
|
BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-5422
|
2024-11-21 14:34 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197932
|
6.5 |
MEDIUM
Network
|
teltonika-networks
|
trb245_firmware
|
Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.
|
CWE-22
Path Traversal
|
CVE-2020-5789
|
2024-11-21 14:34 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197933
|
6.5 |
MEDIUM
Network
|
teltonika-networks
|
trb245_firmware
|
Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/system/admin/certificates/delete action.
|
CWE-22
Path Traversal
|
CVE-2020-5788
|
2024-11-21 14:34 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197934
|
6.5 |
MEDIUM
Network
|
teltonika-networks
|
trb245_firmware
|
Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/services/packages/remove action.
|
CWE-22
Path Traversal
|
CVE-2020-5787
|
2024-11-21 14:34 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197935
|
8.8 |
HIGH
Network
|
teltonika-networks
|
trb245_firmware
|
Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
|
CWE-352
Origin Validation Error
|
CVE-2020-5786
|
2024-11-21 14:34 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197936
|
6.1 |
MEDIUM
Network
|
teltonika-networks
|
trb245_firmware
|
Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.04.3 allows an unauthenticated attacker to conduct reflected cross-site scripting via a crafted ‘action’ or ‘pkg_name’ parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5785
|
2024-11-21 14:34 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197937
|
6.5 |
MEDIUM
Network
|
teltonika-networks
|
trb245_firmware
|
Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the application to perform HTTP GET requests to arbitrary URLs.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-5784
|
2024-11-21 14:34 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197938
|
4.4 |
MEDIUM
Local
|
dell
|
xps_13_9370_firmware
|
Dell XPS 13 9370 BIOS versions prior to 1.13.1 contains an Improper Exception Handling vulnerability. A local attacker with physical access could exploit this vulnerability to prevent the system from…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-5387
|
2024-11-21 14:34 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197939
|
7.5 |
HIGH
Network
|
f5
|
big-iq_centralized_management big-ip_local_traffic_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_analytics big-ip_access_policy_manager big…
|
In BIG-IP 15.0.0-15.1.0.4, 14.1.0-14.1.2.7, 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2 and BIG-IQ 5.2.0-7.1.0, unauthenticated attackers can cause disruption of service via undisclosed met…
|
NVD-CWE-noinfo
|
CVE-2020-5930
|
2024-11-21 14:34 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197940
|
5.9 |
MEDIUM
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_web_application_firewall big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_man…
|
In versions 13.0.0-13.0.0 HF2, 12.1.0-12.1.2 HF1, and 11.6.1-11.6.2, BIG-IP platforms with Cavium Nitrox SSL hardware acceleration cards, a Virtual Server configured with a Client SSL profile, and us…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-5929
|
2024-11-21 14:34 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|