|
195851
|
9.8 |
CRITICAL
Network
|
fortinet
|
fortimail fortivoice
|
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a l…
|
CWE-287
Improper Authentication
|
CVE-2020-9294
|
2024-11-21 14:40 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195852
|
3.7 |
LOW
Network
|
apache oracle debian qos
|
log4j flexcube_private_banking retail_integration_bus flexcube_core_banking peoplesoft_enterprise_peopletools weblogic_server utilities_framework primavera_unifier retail_cust…
|
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log mess…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-9488
|
2024-11-21 14:40 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195853
|
5.5 |
MEDIUM
Local
|
apache oracle
|
tika flexcube_private_banking primavera_unifier webcenter_portal communications_messaging_server
|
A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3P…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-9489
|
2024-11-21 14:40 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195854
|
9.8 |
CRITICAL
Network
|
dlink
|
dsl-2640b_firmware
|
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A hard-coded account allows management-interface login with high privileges. The logged-in user can perform critical tasks and take fu…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-9279
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195855
|
9.1 |
CRITICAL
Network
|
dlink
|
dsl-2640b_firmware
|
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The device can be reset to its default configuration by accessing an unauthenticated URL.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-9278
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195856
|
9.8 |
CRITICAL
Network
|
dlink
|
dsl-2640b_firmware
|
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. Authentication can be bypassed when accessing cgi modules. This allows one to perform administrative tasks (e.g., modify the admin pas…
|
CWE-287
Improper Authentication
|
CVE-2020-9277
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195857
|
8.8 |
HIGH
Network
|
dlink
|
dsl-2640b_firmware
|
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The function do_cgi(), which processes cgi requests supplied to the device's web servers, is vulnerable to a remotely exploitable stac…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-9276
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195858
|
9.8 |
CRITICAL
Network
|
dlink
|
dsl-2640b_firmware
|
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A cfm UDP service listening on port 65002 allows remote, unauthenticated exfiltration of administrative credentials.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-9275
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195859
|
6.1 |
MEDIUM
Network
|
zulip
|
zulip_server
|
Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.
|
CWE-79
Cross-site Scripting
|
CVE-2020-9445
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195860
|
6.1 |
MEDIUM
Network
|
zulip
|
zulip_server
|
Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality.
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-9444
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|