|
196471
|
9.8 |
CRITICAL
Network
|
arubanetworks
|
airwave_glass
|
A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
|
NVD-CWE-noinfo
|
CVE-2020-7127
|
2024-11-21 14:36 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196472
|
5.8 |
MEDIUM
Network
|
arubanetworks
|
airwave_glass
|
A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-7126
|
2024-11-21 14:36 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196473
|
8.8 |
HIGH
Network
|
arubanetworks
|
airwave_glass
|
A remote escalation of privilege vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
|
CWE-269
Improper Privilege Management
|
CVE-2020-7125
|
2024-11-21 14:36 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196474
|
9.8 |
CRITICAL
Network
|
arubanetworks
|
airwave_glass
|
A remote unauthorized access vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
|
NVD-CWE-noinfo
|
CVE-2020-7124
|
2024-11-21 14:36 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196475
|
5.4 |
MEDIUM
Network
|
zte
|
evdc
|
A ZTE product is impacted by an XSS vulnerability. The vulnerability is caused by the lack of correct verification of client data in the WEB module. By inserting malicious scripts into the web module…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6876
|
2024-11-21 14:36 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196476
|
3.1 |
LOW
Network
|
elastic
|
elasticsearch
|
Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when exec…
|
CWE-269
Improper Privilege Management
|
CVE-2020-7020
|
2024-11-21 14:36 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196477
|
6.5 |
MEDIUM
Network
|
fortinet
|
fortios fortiproxy
|
A cleartext storage of sensitive information vulnerability in FortiOS command line interface in versions 6.2.4 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an authenticated attacker …
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-6648
|
2024-11-21 14:36 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196478
|
8.8 |
HIGH
Network
|
hp
|
intelligent_management_center
|
A iccselectrules expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2020-7195
|
2024-11-21 14:36 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196479
|
8.8 |
HIGH
Network
|
hp
|
intelligent_management_center
|
A perfaddormoddevicemonitor expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2020-7194
|
2024-11-21 14:36 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196480
|
8.8 |
HIGH
Network
|
hp
|
intelligent_management_center
|
A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2020-7193
|
2024-11-21 14:36 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|