|
210901
|
7.8 |
HIGH
Local
|
visam
|
vbase_editor vbase_web-remote
|
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module allow weak hashing algorithm and insecure permissions which may allow a local attacker to bypass the password-protected mechanism throu…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-10601
|
2024-11-21 13:55 |
2020-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210902
|
9.8 |
CRITICAL
Network
|
visam
|
vbase_web-remote vbase_editor
|
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow a vulnerable ActiveX component to be exploited resulting in a buffer overflow, which may lead to a denial-of-service conditio…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-10599
|
2024-11-21 13:55 |
2020-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210903
|
6.8 |
MEDIUM
Adjacent
|
eclipse
|
che
|
A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An authenticated user can exploit this flaw to bypass JWT proxy and gain access t…
|
NVD-CWE-Other
|
CVE-2020-10689
|
2024-11-21 13:55 |
2020-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210904
|
9.8 |
CRITICAL
Network
|
starface
|
unified_communication_\&_collaboration_client
|
STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-10515
|
2024-11-21 13:55 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210905
|
6.1 |
MEDIUM
Physics
|
bd
|
pyxis_medstation_es_firmware pyxis_anesthesia_station_es_firmware
|
In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment escape vulnerability exists in the kiosk mode functionality of affected devices. …
|
NVD-CWE-Other
|
CVE-2020-10598
|
2024-11-21 13:55 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210906
|
7.5 |
HIGH
Network
|
tp-link
|
nc450_firmware nc260_firmware nc250_firmware nc230_firmware nc220_firmware nc210_firmware nc200_firmware
|
TP-Link NC200 through 2.1.8_Build_171109, NC210 through 1.0.9_Build_171214, NC220 through 1.3.0_Build_180105, NC230 through 1.3.0_Build_171205, NC250 through 1.3.0_Build_171205, NC260 through 1.5.1_B…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-10231
|
2024-11-21 13:55 |
2020-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210907
|
8.8 |
HIGH
Network
|
buildah_project redhat
|
buildah enterprise_linux openshift_container_platform
|
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write…
|
CWE-22
Path Traversal
|
CVE-2020-10696
|
2024-11-21 13:55 |
2020-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210908
|
9.8 |
CRITICAL
Network
|
pam-krb5_project debian
|
pam-krb5 debian_linux
|
pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental prompting by a Kerberos library. It may overflow a buffer provided by the underly…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-10595
|
2024-11-21 13:55 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210909
|
9.8 |
CRITICAL
Network
|
paessler
|
prtg_network_monitor
|
A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of the screenshot funct…
|
CWE-20
Improper Input Validation
|
CVE-2020-10374
|
2024-11-21 13:55 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210910
|
5.9 |
MEDIUM
Network
|
opensource-socialnetwork
|
open_source_social_network
|
An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserv…
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2020-10560
|
2024-11-21 13:55 |
2020-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|