|
198011
|
9.8 |
CRITICAL
Network
|
vmware oracle
|
spring_integration flexcube_private_banking retail_merchandising_system banking_virtual_account_management banking_credit_facilities_process_management banking_corporate_lending_proces…
|
Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered classes are resolved on d…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-5413
|
2024-11-21 14:34 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198012
|
8.8 |
HIGH
Network
|
vmware
|
gemfire tanzu_gemfire_for_virtual_machines
|
VMware GemFire versions prior to 9.10.0, 9.9.2, 9.8.7, and 9.7.6, and VMware Tanzu GemFire for VMs versions prior to 1.11.1 and 1.10.2, when deployed without a SecurityManager, contain a JMX service …
|
CWE-862
Missing Authorization
|
CVE-2020-5396
|
2024-11-21 14:34 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198013
|
8.4 |
HIGH
Local
|
rsa
|
multifactor_authentication_agent
|
Authentication Bypass Vulnerability RSA MFA Agent 2.0 for Microsoft Windows contains an Authentication Bypass vulnerability. A local unauthenticated attacker could potentially exploit this vulnerabil…
|
CWE-287
Improper Authentication
|
CVE-2020-5384
|
2024-11-21 14:34 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198014
|
7.8 |
HIGH
Local
|
toyota
|
global_techstream
|
Global TechStream (GTS) for TOYOTA dealers version 15.10.032 and earlier allows an attacker to cause a denial-of-service (DoS) condition and execute arbitrary code via unspecified vectors.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-5610
|
2024-11-21 14:34 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198015
|
8.8 |
HIGH
Network
|
grandstream
|
ht801_firmware ht802_firmware ht812_firmware ht814_firmware ht818_firmware ht813_firmware
|
Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can obtain a root shell by correctly answering a challenge prompt.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-5763
|
2024-11-21 14:34 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198016
|
7.5 |
HIGH
Network
|
grandstream
|
ht801_firmware ht802_firmware ht812_firmware ht814_firmware ht818_firmware ht813_firmware
|
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-069 service. An unauthenticated remote attacker can stop the service due to a N…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-5762
|
2024-11-21 14:34 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198017
|
7.5 |
HIGH
Network
|
grandstream
|
ht801_firmware ht802_firmware ht812_firmware ht814_firmware ht818_firmware ht813_firmware
|
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in the TR-069 service. Unauthenticated remote attackers can trigger this case by s…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-5761
|
2024-11-21 14:34 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198018
|
7.8 |
HIGH
Local
|
grandstream
|
ht801_firmware ht802_firmware ht812_firmware ht814_firmware ht818_firmware ht813_firmware
|
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Unauthenticated remote attackers can execute arbitrary commands as root by craftin…
|
CWE-78
OS Command
|
CVE-2020-5760
|
2024-11-21 14:34 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198019
|
5.3 |
MEDIUM
Network
|
kujirahand
|
konawiki
|
Directory traversal vulnerability in KonaWiki 3.1.0 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2020-5614
|
2024-11-21 14:34 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198020
|
6.1 |
MEDIUM
Network
|
kujirahand
|
konawiki
|
Cross-site scripting vulnerability in KonaWiki 3.1.0 and earlier allows remote attackers to execute an arbitrary script via a specially crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5613
|
2024-11-21 14:34 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|