|
199291
|
9.1 |
CRITICAL
Network
|
urve
|
urve
|
An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown the system. Among others, the following files and scripts are also accessible: _…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-29551
|
2024-11-21 14:24 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199292
|
7.5 |
HIGH
Network
|
urve
|
urve
|
An issue was discovered in URVE Build 24.03.2020. The password of an integration user account (used for the connection of the MS Office 365 Integration Service) is stored in cleartext in configuratio…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-29550
|
2024-11-21 14:24 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199293
|
9.8 |
CRITICAL
Network
|
zyxel
|
usg20-vpn_firmware usg20w-vpn_firmware usg40_firmware usg40w_firmware usg60_firmware usg60w_firmware usg110_firmware usg210_firmware usg310_firmware usg1100_firmware usg…
|
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This accoun…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-29583
|
2024-11-21 14:24 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199294
|
7.5 |
HIGH
Network
|
miniweb_http_server_project
|
miniweb_http_server
|
MiniWeb HTTP server 0.8.19 allows remote attackers to cause a denial of service (daemon crash) via a long name for the first parameter in a POST request.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-29596
|
2024-11-21 14:24 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199295
|
4.3 |
MEDIUM
Network
|
atlassian
|
crucible
|
Affected versions of Atlassian Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the file upload request feature of code reviews.…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-29447
|
2024-11-21 14:24 |
2020-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199296
|
7.5 |
HIGH
Network
|
golang
|
ssh
|
A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-29652
|
2024-11-21 14:24 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199297
|
7.2 |
HIGH
Network
|
pluck-cms
|
pluck
|
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remo…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-29607
|
2024-11-21 14:24 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199298
|
9.1 |
CRITICAL
Network
|
icinga
|
icinga
|
Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-29663
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199299
|
7.5 |
HIGH
Network
|
xen
|
xapi
|
An issue was discovered in Xen XAPI before 2020-12-15. Certain xenstore keys provide feedback from the guest, and are therefore watched by toolstack. Specifically, keys are watched by xenopsd, and da…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-29487
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199300
|
5.5 |
MEDIUM
Local
|
xen debian fedoraproject
|
xen debian_linux fedora
|
An issue was discovered in Xen 4.6 through 4.14.x. When acting upon a guest XS_RESET_WATCHES request, not all tracking information is freed. A guest can cause unbounded memory usage in oxenstored. Th…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-29485
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|