|
210971
|
5.3 |
MEDIUM
Local
|
linux fedoraproject opensuse debian canonical netapp
|
linux_kernel fedora leap debian_linux ubuntu_linux cloud_backup element_software steelstore_cloud_integrated_storage solidfire hci_management_node active_iq_unified_mana…
|
The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-12888
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210972
|
7.8 |
HIGH
Local
|
sun-denshi
|
universal_forensic_extraction_device_firmware
|
Cellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command prompt via the Windows file dialog that is reachable via the Certificate-Based…
|
CWE-269
Improper Privilege Management
|
CVE-2020-12798
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210973
|
9.8 |
CRITICAL
Network
|
eq-3
|
homematic_ccu2_firmware ccu3_firmware
|
eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the we…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-12834
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210974
|
6.1 |
MEDIUM
Network
|
redhat
|
interchange
|
XSS in the admin help system admin/help.html and admin/quicklinks.html in Interchange 4.7.0 through 5.11.x allows remote attackers to steal credentials or data via browser JavaScript.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12685
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210975
|
5.4 |
MEDIUM
Network
|
rcos
|
submitty
|
Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a Teaching Fellow.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12882
|
2024-11-21 14:00 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210976
|
7.5 |
HIGH
Network
|
veritas
|
aptare
|
Veritas APTARE versions prior to 10.4 allowed sensitive information to be accessible without authentication.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-12877
|
2024-11-21 14:00 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210977
|
7.5 |
HIGH
Network
|
veritas
|
aptare
|
Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulnerability only impacts Windows server deployments.
|
CWE-863
Incorrect Authorization
|
CVE-2020-12876
|
2024-11-21 14:00 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210978
|
6.3 |
MEDIUM
Network
|
veritas
|
aptare
|
Veritas APTARE versions prior to 10.4 did not perform adequate authorization checks. An authenticated user could gain unauthorized access to sensitive information or functionality by manipulating spe…
|
CWE-863
Incorrect Authorization
|
CVE-2020-12875
|
2024-11-21 14:00 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210979
|
9.8 |
CRITICAL
Network
|
veritas
|
aptare
|
Veritas APTARE versions prior to 10.4 included code that bypassed the normal login process when specific authentication credentials were provided to the server.
|
CWE-287
Improper Authentication
|
CVE-2020-12874
|
2024-11-21 14:00 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210980
|
6.1 |
MEDIUM
Network
|
progress
|
moveit_automation
|
An issue was discovered in Progress MOVEit Automation Web Admin. A Web Admin application endpoint failed to adequately sanitize malicious input, which could allow an unauthenticated attacker to execu…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12677
|
2024-11-21 14:00 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|