|
210601
|
8.2 |
HIGH
Local
|
getcomposer
|
composer-setup
|
In Composer-Setup for Windows before version 6.0.0, if the developer's computer is shared with other users, a local attacker may be able to exploit the following scenarios. 1. A local regular user ma…
|
-
|
CVE-2020-15145
|
2024-11-21 14:04 |
2020-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210602
|
5.9 |
MEDIUM
Physics
|
horndis_project
|
horndis
|
All versions of HoRNDIS are affected by an integer overflow in the RNDIS packet parsing routines. A malicious USB device can trigger disclosure of unrelated kernel memory to userspace applications on…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-15137
|
2024-11-21 14:04 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210603
|
6.1 |
MEDIUM
Network
|
getsymphony
|
symphony
|
content/content.blueprintsevents.php in Symphony CMS 3.0.0 allows XSS via fields['name'] to appendSubheading.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15071
|
2024-11-21 14:04 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210604
|
7.8 |
HIGH
Local
|
evga winring0_project
|
precision_x1 winring0
|
The WinRing0.sys and WinRing0x64.sys drivers 1.2.0 in EVGA Precision X1 through 1.0.6 allow local users, including low integrity processes, to read and write to arbitrary memory locations. This allow…
|
NVD-CWE-noinfo
|
CVE-2020-14979
|
2024-11-21 14:04 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210605
|
6.1 |
MEDIUM
Network
|
mybb
|
mybb
|
In MyBB before version 1.8.24, the custom MyCode (BBCode) for the visual editor doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. The weakness can be expl…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15139
|
2024-11-21 14:04 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210606
|
6.5 |
MEDIUM
Adjacent
|
digitus
|
da-70254_firmware
|
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to denial-of-service the device via long input values.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-15065
|
2024-11-21 14:04 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210607
|
4.3 |
MEDIUM
Adjacent
|
digitus
|
da-70254_firmware
|
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted se…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15064
|
2024-11-21 14:04 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210608
|
8.8 |
HIGH
Adjacent
|
digitus
|
da-70254_firmware
|
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
|
CWE-287
Improper Authentication
|
CVE-2020-15063
|
2024-11-21 14:04 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210609
|
8.8 |
HIGH
Adjacent
|
digitus
|
da-70254_firmware
|
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unenc…
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2020-15062
|
2024-11-21 14:04 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210610
|
6.5 |
MEDIUM
Adjacent
|
lindy-international
|
42633_firmware
|
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to denial-of-service the device via long input values.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-15061
|
2024-11-21 14:04 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|