|
211961
|
9.8 |
CRITICAL
Network
|
articatech
|
web_proxy
|
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.
|
CWE-89
SQL Injection
|
CVE-2020-17506
|
2024-11-21 14:08 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211962
|
8.8 |
HIGH
Network
|
articatech
|
web_proxy
|
Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_…
|
CWE-78
OS Command
|
CVE-2020-17505
|
2024-11-21 14:08 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211963
|
8.1 |
HIGH
Adjacent
|
intel
|
inet_wireless_daemon
|
eapol.c in iNet wireless daemon (IWD) through 1.8 allows attackers to trigger a PTK reinstallation by retransmitting EAPOL Msg4/4.
|
NVD-CWE-noinfo
|
CVE-2020-17497
|
2024-11-21 14:08 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211964
|
9.8 |
CRITICAL
Network
|
magic debian
|
asyncpg debian_linux
|
asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, because of access to an uninitialized poi…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2020-17446
|
2024-11-21 14:08 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211965
|
9.8 |
CRITICAL
Network
|
vbulletin
|
vbulletin
|
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete …
|
CWE-74
Injection
|
CVE-2020-17496
|
2024-11-21 14:08 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211966
|
7.5 |
HIGH
Network
|
django-celery-results_project
|
django-celery-results
|
django-celery-results through 1.2.1 stores task results in the database. Among the data it stores are the variables passed into the tasks. The variables may contain sensitive cleartext information th…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-17495
|
2024-11-21 14:08 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211967
|
4.3 |
MEDIUM
Physics
|
gnome debian canonical opensuse
|
gnome-shell debian_linux ubuntu_linux leap
|
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-17489
|
2024-11-21 14:08 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211968
|
7.5 |
HIGH
Network
|
radare fedoraproject
|
radare2 fedora
|
radare2 4.5.0 misparses signature information in PE files, causing a segmentation fault in r_x509_parse_algorithmidentifier in libr/util/x509.c. This is due to a malformed object identifier in IMAGE_…
|
NVD-CWE-noinfo
|
CVE-2020-17487
|
2024-11-21 14:08 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211969
|
9.8 |
CRITICAL
Network
|
turcom
|
trcwifizone
|
Turcom TRCwifiZone through 2020-08-10 allows authentication bypass by visiting manage/control.php and ignoring 302 Redirect responses.
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2020-17466
|
2024-11-21 14:08 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211970
|
7.8 |
HIGH
Local
|
telegram
|
telegram_desktop
|
Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use of the chat window with a filename that lacks an ex…
|
CWE-863
Incorrect Authorization
|
CVE-2020-17448
|
2024-11-21 14:08 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|