|
211981
|
6.8 |
MEDIUM
Adjacent
|
ti
|
real-time_operating_system z-stack 15.4-stack openthread easylink ble5-stack dynamic_multi-protocal_manager
|
TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile. A LTK can be an unauthenticated-and-no-MITM-protection key created by Just Works or an authenticated-and-MITM-protection key c…
|
CWE-863
Incorrect Authorization
|
CVE-2020-16630
|
2024-11-21 14:07 |
2021-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211982
|
7.5 |
HIGH
Network
|
crestron
|
dm-nvx-dir-80_firmware dm-nvx-dir-160_firmware dm-nvx-dir-ent_firmware
|
On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthenticated WebSocket request.
|
CWE-287
Improper Authentication
|
CVE-2020-16839
|
2024-11-21 14:07 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211983
|
5.4 |
MEDIUM
Network
|
dedecms
|
dedecms
|
A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remote arbitrary code via the keyword parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-16632
|
2024-11-21 14:07 |
2021-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211984
|
8.8 |
HIGH
Network
|
microsoft
|
windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_rt_8.1 windows_server_2019
|
Microsoft Windows Security Feature Bypass Vulnerability
|
NVD-CWE-noinfo
|
CVE-2020-17162
|
2024-11-21 14:07 |
2021-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211985
|
7.8 |
HIGH
Local
|
we-con
|
levistudiou
|
Multiple buffer overflow vulnerabilities exist when LeviStudioU (Version 2019-09-21 and prior) processes project files. Opening a specially crafted project file could allow an attacker to exploit and…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-16243
|
2024-11-21 14:07 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211986
|
9.8 |
CRITICAL
Network
|
phpok
|
phpok
|
PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacement function through api.php to write a PHP file to the targe…
|
CWE-89
SQL Injection
|
CVE-2020-16629
|
2024-11-21 14:07 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211987
|
6.3 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
A heap-based buffer overflow was found in QEMU through 5.0.0 in the SDHCI device emulation support. It could occur while doing a multi block SDMA transfer via the sdhci_sdma_transfer_multi_blocks() r…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-17380
|
2024-11-21 14:07 |
2021-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211988
|
6.1 |
MEDIUM
Network
|
owncloud
|
owncloud
|
ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'
|
CWE-79
Cross-site Scripting
|
CVE-2020-16255
|
2024-11-21 14:07 |
2021-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211989
|
9.9 |
CRITICAL
Network
|
usvn
|
usvn
|
USVN (aka User-friendly SVN) before 1.0.9 allows remote code execution via shell metacharacters in the number_start or number_end parameter to LastHundredRequest (aka lasthundredrequestAction) in the…
|
CWE-78
OS Command
|
CVE-2020-17363
|
2024-11-21 14:07 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211990
|
8.8 |
HIGH
Network
|
1e
|
client
|
The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the repair option. This applies to installations that have a T…
|
CWE-74 CWE-668
Injection Exposure of Resource to Wrong Sphere
|
CVE-2020-16268
|
2024-11-21 14:07 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|