|
210811
|
4.1 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The __mptctl_ioctl function in drivers/message/fusion/mptctl.c in the Linux kernel before 5.4.14 allows local users to hold an incorrect lock during the ioctl operation and trigger a race condition, …
|
CWE-362
Race Condition
|
CVE-2020-12652
|
2024-11-21 13:59 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210812
|
7.5 |
HIGH
Network
|
gurbalib_project
|
gurbalib
|
Gurbalib through 2020-04-30 allows lib/cmds/player/help.c directory traversal for reading administrative paths.
|
CWE-22
Path Traversal
|
CVE-2020-12649
|
2024-11-21 13:59 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210813
|
7.5 |
HIGH
Network
|
reportportal
|
service-api
|
An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resultant secrets disclosure and SSRF, via JUnit XML launch import.
|
CWE-611
XXE
|
CVE-2020-12642
|
2024-11-21 13:59 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210814
|
8.8 |
HIGH
Network
|
tp-link
|
nc200_firmware nc210_firmware nc220_firmware nc230_firmware nc250_firmware nc260_firmware nc450_firmware
|
Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1…
|
CWE-78
OS Command
|
CVE-2020-12109
|
2024-11-21 13:59 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210815
|
9.8 |
CRITICAL
Network
|
roundcube opensuse
|
webmail leap backports_sle
|
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
|
CWE-78
OS Command
|
CVE-2020-12641
|
2024-11-21 13:59 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210816
|
9.8 |
CRITICAL
Network
|
roundcube opensuse
|
webmail leap backports_sle
|
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
|
CWE-22
Path Traversal
|
CVE-2020-12640
|
2024-11-21 13:59 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210817
|
8.8 |
HIGH
Network
|
tp-link
|
nc260_firmware nc450_firmware
|
Certain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304.
|
CWE-78
OS Command
|
CVE-2020-12111
|
2024-11-21 13:59 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210818
|
6.1 |
MEDIUM
Network
|
phplist
|
phplist
|
phpList before 3.5.3 allows XSS, with resultant privilege elevation, via lists/admin/template.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12639
|
2024-11-21 13:59 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210819
|
5.5 |
MEDIUM
Local
|
tp-link
|
omada_controller
|
TP-Link Omada Controller Software 3.2.6 allows Directory Traversal for reading arbitrary files via com.tp_link.eap.web.portal.PortalController.getAdvertiseFile in /opt/tplink/EAPController/lib/eap-we…
|
CWE-22
Path Traversal
|
CVE-2020-12475
|
2024-11-21 13:59 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210820
|
9.8 |
CRITICAL
Network
|
tp-link
|
nc200_firmware nc210_firmware nc220_firmware nc230_firmware nc250_firmware nc260_firmware nc450_firmware
|
Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-12110
|
2024-11-21 13:59 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|