|
198291
|
8.8 |
HIGH
Network
|
gocloud
|
s2a_wl_firmware s2a_firmware s3a_k2p_mtk_firmware s3a_firmware isp3000_firmware
|
Gocloud S2A_WL 4.2.7.16471, S2A 4.2.7.17278, S2A 4.3.0.15815, S2A 4.3.0.17193, S3A K2P MTK 4.2.7.16528, S3A 4.3.0.16572, and ISP3000 4.3.0.17190 devices allows remote attackers to execute arbitrary O…
|
CWE-78
OS Command
|
CVE-2020-8949
|
2024-11-21 14:39 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198292
|
7.2 |
HIGH
Network
|
artica
|
pandora_fms
|
functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the index.php?operation/netflow/nf_live_view ip_dst, dst_port, or …
|
CWE-78
OS Command
|
CVE-2020-8947
|
2024-11-21 14:39 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198293
|
8.8 |
HIGH
Network
|
netis-systems
|
wf2471_firmware
|
Netis WF2471 v1.2.30142 devices allow an authenticated attacker to execute arbitrary OS commands via shell metacharacters in the /cgi-bin-igd/sys_log_clean.cgi log_3g_type parameter.
|
CWE-78
OS Command
|
CVE-2020-8946
|
2024-11-21 14:39 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198294
|
7.5 |
HIGH
Network
|
gpgme_project redhat fedoraproject
|
gpgme openshift_container_platform openshift_container_platform_for_ibm_z openshift_container_platform_for_linuxone fedora enterprise_linux_workstation enterprise_linux_server en…
|
The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code executi…
|
CWE-416
Use After Free
|
CVE-2020-8945
|
2024-11-21 14:39 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198295
|
6.1 |
MEDIUM
Network
|
chiyu-t
|
bf-430_firmware
|
Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cgi TF_submask field.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8839
|
2024-11-21 14:39 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198296
|
7.5 |
HIGH
Network
|
iktm
|
bearftp
|
Improper connection handling in the base connection handler in IKTeam BearFTP before v0.3.1 allows a remote attacker to achieve denial of service via a Slowloris approach by sending a large volume of…
|
CWE-20
Improper Input Validation
|
CVE-2020-8815
|
2024-11-21 14:39 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198297
|
7.3 |
HIGH
Network
|
istio redhat
|
istio openshift_service_mesh
|
Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact-path matching logic can allow unauthorized access…
|
CWE-287
Improper Authentication
|
CVE-2020-8595
|
2024-11-21 14:39 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198298
|
6.5 |
MEDIUM
Network
|
misp
|
misp
|
An issue was discovered in MISP before 2.4.121. ACLs for discussion threads were mishandled in app/Controller/ThreadsController.php and app/Model/Thread.php.
|
NVD-CWE-noinfo
|
CVE-2020-8894
|
2024-11-21 14:39 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198299
|
7.5 |
HIGH
Network
|
misp
|
misp
|
An issue was discovered in MISP before 2.4.121. The Galaxy view contained an incorrectly sanitized search string in app/View/Galaxies/view.ctp.
|
NVD-CWE-noinfo
|
CVE-2020-8893
|
2024-11-21 14:39 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198300
|
8.1 |
HIGH
Network
|
misp
|
misp
|
An issue was discovered in MISP before 2.4.121. It did not consider the HTTP PUT method when trying to block a brute-force series of invalid requests.
|
NVD-CWE-noinfo
|
CVE-2020-8892
|
2024-11-21 14:39 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|