|
211371
|
5.3 |
MEDIUM
Network
|
grin
|
grin
|
Grin before 3.1.0 allows attackers to adversely affect availability of data on a Mimblewimble blockchain.
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2020-12439
|
2024-11-21 13:59 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211372
|
4.9 |
MEDIUM
Network
|
silver-peak
|
unity_edgeconnect_for_google_cloud_platform unity_edgeconnect_for_azure unity_edgeconnect_for_amazon_web_services unity_orchestrator vx-500_firmware vx-1000_firmware vx-2000_firmwar…
|
The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeConnect to an untruste…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-12144
|
2024-11-21 13:59 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211373
|
4.9 |
MEDIUM
Network
|
silver-peak
|
unity_edgeconnect_for_google_cloud_platform unity_edgeconnect_for_azure unity_edgeconnect_for_amazon_web_services unity_orchestrator vx-500_firmware vx-1000_firmware vx-2000_firmwar…
|
The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-12143
|
2024-11-21 13:59 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211374
|
4.9 |
MEDIUM
Network
|
silver-peak
|
unity_edgeconnect_for_google_cloud_platform unity_edgeconnect_for_azure unity_edgeconnect_for_amazon_web_services unity_orchestrator vx-500_firmware vx-1000_firmware vx-2000_firmwar…
|
1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could …
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-12142
|
2024-11-21 13:59 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211375
|
8.8 |
HIGH
Network
|
internet-formation
|
wp-advanced-search
|
The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands withou…
|
CWE-89
SQL Injection
|
CVE-2020-12104
|
2024-11-21 13:59 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211376
|
7.8 |
HIGH
Local
|
linux opensuse debian netapp
|
linux_kernel leap debian_linux cloud_backup element_software steelstore_cloud_integrated_storage solidfire hci_management_node active_iq_unified_manager hci_compute_node_fi…
|
An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marvell/mwifiex/scan.c allows local users to gain privileges or cause a denial of s…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12653
|
2024-11-21 13:59 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211377
|
7.1 |
HIGH
Adjacent
|
linux
|
linux_kernel
|
An issue was found in Linux kernel before 5.5.4. mwifiex_ret_wmm_get_status() in drivers/net/wireless/marvell/mwifiex/wmm.c allows a remote AP to trigger a heap-based buffer overflow because of an in…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12654
|
2024-11-21 13:59 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211378
|
4.1 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The __mptctl_ioctl function in drivers/message/fusion/mptctl.c in the Linux kernel before 5.4.14 allows local users to hold an incorrect lock during the ioctl operation and trigger a race condition, …
|
CWE-362
Race Condition
|
CVE-2020-12652
|
2024-11-21 13:59 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211379
|
7.5 |
HIGH
Network
|
gurbalib_project
|
gurbalib
|
Gurbalib through 2020-04-30 allows lib/cmds/player/help.c directory traversal for reading administrative paths.
|
CWE-22
Path Traversal
|
CVE-2020-12649
|
2024-11-21 13:59 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211380
|
7.5 |
HIGH
Network
|
reportportal
|
service-api
|
An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resultant secrets disclosure and SSRF, via JUnit XML launch import.
|
CWE-611
XXE
|
CVE-2020-12642
|
2024-11-21 13:59 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|