|
196771
|
6.5 |
MEDIUM
Network
|
bosch
|
video_management_system_viewer video_management_system
|
A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated remote attacker to read arbitrary files from the Central Server. This affects Bo…
|
CWE-22
Path Traversal
|
CVE-2020-6767
|
2024-11-21 14:36 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196772
|
5.4 |
MEDIUM
Network
|
sos-berlin
|
jobscheduler
|
A cross-site scripting (XSS) vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to inject arbitrary web script or HTML via JSON properties available from …
|
CWE-79
Cross-site Scripting
|
CVE-2020-6854
|
2024-11-21 14:36 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196773
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.
|
NVD-CWE-noinfo
|
CVE-2020-6833
|
2024-11-21 14:36 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196774
|
9.8 |
CRITICAL
Network
|
dotcms
|
dotcms
|
dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2020-6754
|
2024-11-21 14:36 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196775
|
9.8 |
CRITICAL
Network
|
automationdirect
|
c-more_ea9-rhi_firmware c-more_ea9-t6cl-r_firmware c-more_ea9-t6cl_firmware c-more_ea9-t7cl-r_firmware c-more_ea9-t7cl_firmware c-more_ea9-t8cl_firmware c-more_ea9-t10cl_firmware
|
It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an attacker to remotely access the C-More Touch Panels EA9 series: firmware versio…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-6969
|
2024-11-21 14:36 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196776
|
7.5 |
HIGH
Network
|
opensuse
|
wicked leap
|
An ni_dhcp4_parse_response memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets without a message type option.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-7216
|
2024-11-21 14:36 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196777
|
7.8 |
HIGH
Local
|
mariadb
|
mariadb
|
mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack …
|
CWE-59
Link Following
|
CVE-2020-7221
|
2024-11-21 14:36 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196778
|
7.5 |
HIGH
Network
|
hashicorp
|
consul
|
HashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 1.6.3.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-7219
|
2024-11-21 14:36 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196779
|
7.5 |
HIGH
Network
|
hashicorp
|
nomad
|
HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 0.10.3.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-7218
|
2024-11-21 14:36 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196780
|
9.8 |
CRITICAL
Network
|
openbsd debian fedoraproject canonical
|
opensmtpd debian_linux fedora ubuntu_linux
|
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated …
|
CWE-78 CWE-755
OS Command Improper Handling of Exceptional Conditions
|
CVE-2020-7247
|
2024-11-21 14:36 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|