|
212021
|
8.8 |
HIGH
Network
|
intel
|
bmc_firmware
|
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a Cross-Site Request Forgery (CSRF) vulnerability in the AMI BMC firmware in which the web application does not suf…
|
CWE-352
Origin Validation Error
|
CVE-2020-11485
|
2024-11-21 13:57 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212022
|
4.9 |
MEDIUM
Network
|
intel
|
bmc_firmware
|
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a vulnerability in the AMI BMC firmware in which an attacker with administrative privileges can obtain the hash of …
|
NVD-CWE-noinfo
|
CVE-2020-11484
|
2024-11-21 13:57 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212023
|
9.8 |
CRITICAL
Network
|
intel
|
bmc_firmware
|
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which the firm…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-11483
|
2024-11-21 13:57 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212024
|
7.2 |
HIGH
Network
|
concretecms
|
concrete_cms
|
Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-11476
|
2024-11-21 13:57 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212025
|
7.8 |
HIGH
Local
|
ncp-e
|
secure_enterprise_client
|
NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant.
|
CWE-59
Link Following
|
CVE-2020-11474
|
2024-11-21 13:57 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212026
|
7.5 |
HIGH
Network
|
windriver
|
vxworks
|
httpRpmFs in WebCLI in Wind River VxWorks 5.5 through 7 SR0640 has no check for an escape from the web root.
|
NVD-CWE-noinfo
|
CVE-2020-11440
|
2024-11-21 13:57 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212027
|
8.8 |
HIGH
Network
|
librehealth
|
librehealth_ehr
|
LibreHealth EMR v2.0.0 is affected by a Local File Inclusion issue allowing arbitrary PHP to be included and executed within the EMR application.
|
CWE-22
Path Traversal
|
CVE-2020-11439
|
2024-11-21 13:57 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212028
|
8.8 |
HIGH
Network
|
librehealth
|
librehealth_ehr
|
LibreHealth EMR v2.0.0 is affected by systemic CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-11438
|
2024-11-21 13:57 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212029
|
4.3 |
MEDIUM
Network
|
librehealth
|
librehealth_ehr
|
LibreHealth EMR v2.0.0 is affected by SQL injection allowing low-privilege authenticated users to enumerate the database.
|
CWE-89
SQL Injection
|
CVE-2020-11437
|
2024-11-21 13:57 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212030
|
9.0 |
CRITICAL
Network
|
librehealth
|
librehealth_ehr
|
LibreHealth EMR v2.0.0 is vulnerable to XSS that results in the ability to force arbitrary actions on behalf of other users including administrators.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11436
|
2024-11-21 13:57 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|