|
211051
|
9.8 |
CRITICAL
Network
|
panasonic
|
eluga_ray_530_firmware eluga_ray_600_firmware p110_firmware eluga_z1_pro_firmware eluga_x1_firmware eluga_x1_pro_firmware
|
Panasonic P110, Eluga Z1 Pro, Eluga X1, and Eluga X1 Pro devices through 2020-04-10 have Insecure Permissions. NOTE: the vendor states that all affected products are at "End-of-software-support."
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-11716
|
2024-11-21 13:58 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211052
|
8.8 |
HIGH
Network
|
ifax avantfax
|
hylafax avantfax
|
sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection.
|
CWE-78
OS Command
|
CVE-2020-11766
|
2024-11-21 13:58 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211053
|
9.8 |
CRITICAL
Network
|
panasonic
|
p99_firmware
|
Panasonic P99 devices through 2020-04-10 have Incorrect Access Control. NOTE: the vendor states that all affected products are at "End-of-software-support."
|
NVD-CWE-noinfo
|
CVE-2020-11715
|
2024-11-21 13:58 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211054
|
7.8 |
HIGH
Local
|
sourcefabric
|
newscoop
|
Because of Unrestricted Upload of a File with a Dangerous Type, Sourcefabric Newscoop 4.4.7 allows an authenticated user to execute arbitrary PHP code (and sometimes terminal commands) on a server by…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-11807
|
2024-11-21 13:58 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211055
|
6.1 |
MEDIUM
Network
|
microfocus
|
service_manager
|
Cross Site Scripting vulnerability in Micro Focus Service Manager product. Affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. The vulnerability could be exploited to allow remote attackers …
|
CWE-79
Cross-site Scripting
|
CVE-2020-11845
|
2024-11-21 13:58 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211056
|
6.5 |
MEDIUM
Adjacent
|
netgear
|
rbs50y_firmware srr60_firmware srs60_firmware
|
An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 …
|
NVD-CWE-noinfo
|
CVE-2020-11550
|
2024-11-21 13:58 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211057
|
8.8 |
HIGH
Adjacent
|
netgear
|
rbs50y_firmware srr60_firmware srs60_firmware
|
An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-11549
|
2024-11-21 13:58 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211058
|
8.8 |
HIGH
Adjacent
|
netgear
|
rbs50y_firmware srr60_firmware srs60_firmware
|
An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 …
|
CWE-287 CWE-330
Improper Authentication Use of Insufficiently Random Values
|
CVE-2020-11551
|
2024-11-21 13:58 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211059
|
2.2 |
LOW
Network
|
freerdp canonical opensuse debian
|
freerdp ubuntu_linux leap debian_linux
|
libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read.
|
CWE-125 CWE-190
Out-of-bounds Read Integer Overflow or Wraparound
|
CVE-2020-11526
|
2024-11-21 13:58 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211060
|
2.2 |
LOW
Network
|
freerdp debian canonical opensuse
|
freerdp debian_linux ubuntu_linux leap
|
libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-11525
|
2024-11-21 13:58 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|