|
212381
|
8.8 |
HIGH
Adjacent
|
tp-link
|
ac1750_firmware
|
This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to explo…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-10884
|
2024-11-21 13:56 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212382
|
7.8 |
HIGH
Local
|
tp-link
|
ac1750_firmware
|
This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. An attacker must first obtain the ability to execu…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-10883
|
2024-11-21 13:56 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212383
|
8.8 |
HIGH
Adjacent
|
tp-link
|
ac1750_firmware
|
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to ex…
|
CWE-78
OS Command
|
CVE-2020-10882
|
2024-11-21 13:56 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212384
|
9.8 |
CRITICAL
Network
|
tp-link
|
ac1750_firmware
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10881
|
2024-11-21 13:56 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212385
|
9.1 |
CRITICAL
Network
|
it-novum
|
openitcockpit
|
openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-10788
|
2024-11-21 13:56 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212386
|
6.5 |
MEDIUM
Network
|
it-novum
|
openitcockpit
|
app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connect…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-10791
|
2024-11-21 13:56 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212387
|
5.4 |
MEDIUM
Network
|
it-novum
|
openitcockpit
|
openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10790
|
2024-11-21 13:56 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212388
|
9.8 |
CRITICAL
Network
|
it-novum
|
openitcockpit
|
openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageInt…
|
CWE-78
OS Command
|
CVE-2020-10789
|
2024-11-21 13:56 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212389
|
5.3 |
MEDIUM
Local
|
linux opensuse debian canonical
|
linux_kernel leap debian_linux ubuntu_linux
|
In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10942
|
2024-11-21 13:56 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212390
|
5.9 |
MEDIUM
Network
|
arm fedoraproject debian
|
mbed_crypto mbed_tls fedora debian_linux
|
Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import.
|
NVD-CWE-noinfo
|
CVE-2020-10941
|
2024-11-21 13:56 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|