|
197731
|
4.3 |
MEDIUM
Network
|
mahara
|
mahara
|
In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' i…
|
CWE-200
Information Exposure
|
CVE-2020-9387
|
2024-11-21 14:40 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197732
|
6.5 |
MEDIUM
Network
|
apache
|
nifi_registry
|
If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Registry invalidates the authentication token on the client side but not on the ser…
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-9482
|
2024-11-21 14:40 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197733
|
7.5 |
HIGH
Network
|
apache debian
|
traffic_server debian_linux
|
Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-9481
|
2024-11-21 14:40 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197734
|
9.8 |
CRITICAL
Network
|
fortinet
|
fortimail fortivoice
|
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a l…
|
CWE-287
Improper Authentication
|
CVE-2020-9294
|
2024-11-21 14:40 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197735
|
3.7 |
LOW
Network
|
apache oracle debian qos
|
log4j flexcube_private_banking retail_integration_bus flexcube_core_banking peoplesoft_enterprise_peopletools weblogic_server utilities_framework primavera_unifier retail_cust…
|
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log mess…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-9488
|
2024-11-21 14:40 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197736
|
5.5 |
MEDIUM
Local
|
apache oracle
|
tika flexcube_private_banking primavera_unifier webcenter_portal communications_messaging_server
|
A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3P…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-9489
|
2024-11-21 14:40 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197737
|
9.8 |
CRITICAL
Network
|
dlink
|
dsl-2640b_firmware
|
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A hard-coded account allows management-interface login with high privileges. The logged-in user can perform critical tasks and take fu…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-9279
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197738
|
9.1 |
CRITICAL
Network
|
dlink
|
dsl-2640b_firmware
|
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The device can be reset to its default configuration by accessing an unauthenticated URL.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-9278
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197739
|
9.8 |
CRITICAL
Network
|
dlink
|
dsl-2640b_firmware
|
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. Authentication can be bypassed when accessing cgi modules. This allows one to perform administrative tasks (e.g., modify the admin pas…
|
CWE-287
Improper Authentication
|
CVE-2020-9277
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197740
|
8.8 |
HIGH
Network
|
dlink
|
dsl-2640b_firmware
|
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The function do_cgi(), which processes cgi requests supplied to the device's web servers, is vulnerable to a remotely exploitable stac…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-9276
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|