|
210611
|
4.3 |
MEDIUM
Adjacent
|
lindy-international
|
42633_firmware
|
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted se…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15060
|
2024-11-21 14:04 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210612
|
8.8 |
HIGH
Adjacent
|
lindy-international
|
42633_firmware
|
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
|
CWE-287
Improper Authentication
|
CVE-2020-15059
|
2024-11-21 14:04 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210613
|
8.8 |
HIGH
Adjacent
|
lindy-international
|
42633_firmware
|
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unenc…
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2020-15058
|
2024-11-21 14:04 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210614
|
6.5 |
MEDIUM
Adjacent
|
tp-link
|
tl-ps310u_firmware
|
TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to denial-of-service the device via long input values.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-15057
|
2024-11-21 14:04 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210615
|
4.3 |
MEDIUM
Adjacent
|
tp-link
|
tl-ps310u_firmware
|
TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted se…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15056
|
2024-11-21 14:04 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210616
|
8.8 |
HIGH
Adjacent
|
tp-link
|
tl-ps310u_firmware
|
TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
|
CWE-287
Improper Authentication
|
CVE-2020-15055
|
2024-11-21 14:04 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210617
|
8.8 |
HIGH
Adjacent
|
tp-link
|
tl-ps310u_firmware
|
TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unenc…
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2020-15054
|
2024-11-21 14:04 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210618
|
7.5 |
HIGH
Network
|
prismjs
|
previewers
|
Prism is vulnerable to Cross-Site Scripting. The easing preview of the Previewers plugin has an XSS vulnerability that allows attackers to execute arbitrary code in Safari and Internet Explorer. This…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15138
|
2024-11-21 14:04 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210619
|
7.7 |
HIGH
Network
|
redhat fedoraproject
|
etcd fedora
|
In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoin…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2020-15114
|
2024-11-21 14:04 |
2020-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210620
|
6.5 |
MEDIUM
Network
|
redhat fedoraproject
|
etcd fedora
|
In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on e…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-15136
|
2024-11-21 14:04 |
2020-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|