|
208701
|
7.5 |
HIGH
Network
|
cpanel
|
cpanel
|
In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).
|
CWE-521
Weak Password Requirements
|
CVE-2020-26103
|
2024-11-21 14:19 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208702
|
7.5 |
HIGH
Network
|
cpanel
|
cpanel
|
In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550).
|
NVD-CWE-noinfo
|
CVE-2020-26102
|
2024-11-21 14:19 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208703
|
9.8 |
CRITICAL
Network
|
cpanel
|
cpanel
|
In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).
|
CWE-287
Improper Authentication
|
CVE-2020-26101
|
2024-11-21 14:19 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208704
|
9.8 |
CRITICAL
Network
|
cpanel
|
cpanel
|
chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497).
|
NVD-CWE-Other
|
CVE-2020-26100
|
2024-11-21 14:19 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208705
|
7.5 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491).
|
NVD-CWE-Other
|
CVE-2020-26099
|
2024-11-21 14:19 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208706
|
9.8 |
CRITICAL
Network
|
cpanel
|
cpanel
|
cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).
|
NVD-CWE-noinfo
|
CVE-2020-26098
|
2024-11-21 14:19 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208707
|
5.5 |
MEDIUM
Local
|
linux debian opensuse canonical
|
linux_kernel debian_linux leap ubuntu_linux
|
A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets, bypassing security mechanisms, aka CID…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-26088
|
2024-11-21 14:19 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208708
|
- |
|
-
|
-
|
Exposure of Sensitive Information
to an Unauthorized Access vulnerability in OpenText NetIQ Directory and
Resource Administrator. This issue affects NetIQ Directory and Resource
Administrator version…
|
-
|
CVE-2020-25836
|
2024-11-21 14:18 |
2024-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208709
|
5.4 |
MEDIUM
Network
|
microfocus
|
arcsight_management_center
|
A potential vulnerability has been identified in Micro Focus ArcSight Management Center. The vulnerability could be remotely exploited resulting in stored Cross-Site Scripting (XSS).
|
CWE-79
Cross-site Scripting
|
CVE-2020-25835
|
2024-11-21 14:18 |
2023-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208710
|
- |
|
-
|
-
|
Cross Site Scripting (XSS) vulnerability in ZoneMinder before version 1.34.21, allows remote attackers execute arbitrary code, escalate privileges, and obtain sensitive information via PHP_SELF compo…
|
-
|
CVE-2020-25730
|
2024-11-21 14:18 |
2024-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|