|
209861
|
7.5 |
HIGH
Network
|
arista
|
cloudvision_exchange
|
Arista’s CloudVision eXchange (CVX) server before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (crash and res…
|
NVD-CWE-noinfo
|
CVE-2020-13100
|
2024-11-21 14:00 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209862
|
5.5 |
MEDIUM
Local
|
amd
|
atikmdag.sys
|
A denial of service vulnerability exists in the D3DKMTEscape handler functionality of AMD ATIKMDAG.SYS (e.g. version 26.20.15029.27017). A specially crafted D3DKMTEscape API request can cause an out-…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-12933
|
2024-11-21 14:00 |
2020-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209863
|
7.8 |
HIGH
Local
|
amd
|
ryzen_master
|
A vulnerability in a dynamically loaded AMD driver in AMD Ryzen Master V15 may allow any authenticated user to escalate privileges to NT authority system.
|
NVD-CWE-noinfo
|
CVE-2020-12928
|
2024-11-21 14:00 |
2020-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209864
|
5.5 |
MEDIUM
Local
|
amd
|
atikmdag.sys
|
A denial of service vulnerability exists in the D3DKMTCreateAllocation handler functionality of AMD ATIKMDAG.SYS (e.g. version 26.20.15029.27017). A specially crafted D3DKMTCreateAllocation API reque…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-12911
|
2024-11-21 14:00 |
2020-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209865
|
6.1 |
MEDIUM
Network
|
webmin
|
webmin
|
XSS exists in Webmin 1.941 and earlier affecting the Save function of the Read User Email Module / mailboxes Endpoint when attempting to save HTML emails. This module parses any output without saniti…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12670
|
2024-11-21 14:00 |
2020-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209866
|
9.1 |
CRITICAL
Network
|
fusionauth
|
samlv2
|
FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack".
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-12676
|
2024-11-21 14:00 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209867
|
6.1 |
MEDIUM
Network
|
sysaid
|
sysaidsy_on-premises sysaid_on-premises
|
SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13168
|
2024-11-21 14:00 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209868
|
9.8 |
CRITICAL
Network
|
rainbowfishsoftware
|
pacsone_server
|
RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page.
|
CWE-89
SQL Injection
|
CVE-2020-12870
|
2024-11-21 14:00 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209869
|
5.4 |
MEDIUM
Network
|
rainbowfishsoftware
|
pacsone_server
|
RainbowFish PacsOne Server 6.8.4 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12869
|
2024-11-21 14:00 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209870
|
8.8 |
HIGH
Network
|
rainbowfishsoftware
|
pacsone_server
|
RainbowFish PacsOne Server 6.8.4 has Incorrect Access Control.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-12715
|
2024-11-21 14:00 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|