|
210681
|
8.8 |
HIGH
Network
|
monstra
|
monstra
|
Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, for example, .php filenames are blocked but .php7 filenames a…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-13384
|
2024-11-21 14:01 |
2020-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210682
|
7.8 |
HIGH
Local
|
amd
|
enterprise_driver radeon_pro_software radeon_software ryzen_3_2200ge_firmware ryzen_3_2200g_firmware ryzen_5_2400ge_firmware ryzen_5_2400g_firmware ryzen_3_3100_firmware ryzen…
|
Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.
|
NVD-CWE-Other
|
CVE-2020-12931
|
2024-11-21 14:00 |
2022-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210683
|
7.8 |
HIGH
Local
|
amd
|
enterprise_driver radeon_pro_software radeon_software radeon_rx_vega_56_firmware radeon_rx_vega_64_firmware ryzen_3_2200ge_firmware ryzen_3_2200g_firmware ryzen_5_2400ge_firmware…
|
Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.
|
NVD-CWE-Other
|
CVE-2020-12930
|
2024-11-21 14:00 |
2022-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210684
|
7.8 |
HIGH
Local
|
verint
|
desktop_and_process_analytics
|
The MSI installer in Verint Desktop Resources 15.2 allows an unprivileged local user to elevate their privileges during install or repair.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-12744
|
2024-11-21 14:00 |
2022-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210685
|
9.8 |
CRITICAL
Network
|
moica
|
hicos
|
Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated remote attacker can exploit this vulnerability to pe…
|
CWE-78
OS Command
|
CVE-2020-12775
|
2024-11-21 14:00 |
2022-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210686
|
5.5 |
MEDIUM
Local
|
amd
|
epyc_7763_firmware epyc_7713p_firmware epyc_7713_firmware epyc_7663_firmware epyc_7643_firmware epyc_75f3_firmware epyc_7543p_firmware epyc_7543_firmware epyc_7513_firmware
|
AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure Encrypted Virtualization with Secure Nested Paging…
|
CWE-200
Information Exposure
|
CVE-2020-12966
|
2024-11-21 14:00 |
2022-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210687
|
7.8 |
HIGH
Local
|
amd
|
radeon_software radeon_pro_software
|
AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-12891
|
2024-11-21 14:00 |
2022-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210688
|
7.5 |
HIGH
Network
|
amd
|
ryzen_pro_5650g_firmware ryzen_pro_5650ge_firmware ryzen_pro_5750g_firmware ryzen_pro_5750ge_firmware ryzen_pro_5350g_firmware ryzen_pro_5350ge_firmware ryzen_pro_4750g_firmware …
|
When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using only the lower 48 address bits potentially resulting in data leakage.
|
CWE-74
Injection
|
CVE-2020-12965
|
2024-11-21 14:00 |
2022-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210689
|
6.7 |
MEDIUM
Local
|
amd
|
amd_generic_encapsulated_software_architecture
|
Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or administrative access to potentially manipulate the AMD Generic En…
|
NVD-CWE-noinfo
|
CVE-2020-12890
|
2024-11-21 14:00 |
2021-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210690
|
7.8 |
HIGH
Local
|
amd
|
epyc_7003_firmware epyc_7002_firmware epyc_72f3_firmware epyc_7313_firmware epyc_7313p_firmware epyc_7343_firmware epyc_73f3_firmware epyc_7413_firmware epyc_7443_firmware …
|
A potential vulnerability exists in AMD Platform Security Processor (PSP) that may allow an attacker to zero any privileged register on the System Management Network which may lead to bypassing SPI R…
|
NVD-CWE-noinfo
|
CVE-2020-12961
|
2024-11-21 14:00 |
2021-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|