|
210591
|
7.5 |
HIGH
Network
|
cauldrondevelopment
|
c\!
|
tar/TarFileReader.cpp in Cauldron cbang (aka C-Bang or C!) before 1.6.0 allows Directory Traversal during extraction from a TAR archive.
|
CWE-22
Path Traversal
|
CVE-2020-15908
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210592
|
7.8 |
HIGH
Local
|
pypi
|
bsdiff4
|
A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond allocated bounds) via a crafted patch file.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-15904
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210593
|
6.1 |
MEDIUM
Network
|
nagios
|
nagios_xi
|
Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15902
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210594
|
8.8 |
HIGH
Network
|
nagios
|
nagios_xi
|
In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys.
|
NVD-CWE-noinfo
|
CVE-2020-15901
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210595
|
6.1 |
MEDIUM
Network
|
dlink
|
dir-816l_firmware
|
An XSS issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. In the file webinc/js/info.php, no output filtration is applied to the RESULT parameter, before it's printed on the we…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15895
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210596
|
7.5 |
HIGH
Network
|
dlink
|
dir-816l_firmware
|
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. There exists an exposed administration function in getcfg.php, which can be used to call various services. It can be utili…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-15894
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210597
|
7.5 |
HIGH
Network
|
dlink
|
dap-1522_firmware
|
An authentication-bypass issue was discovered on D-Link DAP-1522 devices 1.4x before 1.10b04Beta02. There exist a few pages that are directly accessible by any unauthorized user, e.g., logout.php and…
|
CWE-287
Improper Authentication
|
CVE-2020-15896
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210598
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-816l_firmware
|
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting …
|
CWE-78
OS Command
|
CVE-2020-15893
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210599
|
9.8 |
CRITICAL
Network
|
dlink
|
dap-1520_firmware
|
An issue was discovered in apply.cgi on D-Link DAP-1520 devices before 1.10b04Beta02. Whenever a user performs a login action from the web interface, the request values are being forwarded to the ssi…
|
CWE-787 CWE-669
Out-of-bounds Write Incorrect Resource Transfer Between Spheres
|
CVE-2020-15892
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210600
|
7.5 |
HIGH
Network
|
codesys
|
control_rte control_for_beaglebone control_for_empc-a\/imx6 control_for_iot2000 control_for_linux control_for_plcnext control_for_pfc100 control_for_pfc200 control_for_raspber…
|
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-15806
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|