|
208241
|
7.5 |
HIGH
Network
|
basetech
|
ge-131_bt-1837836_firmware
|
In BASETech GE-131 BT-1837836 firmware 20180921, the web-server on the system is configured with the option “DocumentRoot /etc“. This allows an attacker with network access to the web-server to downl…
|
CWE-22
Path Traversal
|
CVE-2020-27553
|
2024-11-21 14:21 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208242
|
9.9 |
CRITICAL
Network
|
garmin
|
forerunner_235_firmware
|
Garmin Forerunner 235 before 8.20 is affected by: Buffer Overflow. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerability, the attacker must upload a malicious ConnectIQ …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-27486
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208243
|
9.9 |
CRITICAL
Network
|
garmin
|
forerunner_235_firmware
|
Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerability, the attacker must upload a malicious ConnectI…
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-27485
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208244
|
9.9 |
CRITICAL
Network
|
garmin
|
forerunner_235_firmware
|
Garmin Forerunner 235 before 8.20 is affected by: Integer Overflow. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerability, the attacker must upload a malicious ConnectIQ…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-27484
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208245
|
9.9 |
CRITICAL
Network
|
garmin
|
forerunner_235_firmware
|
Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerability, the attacker must upload a malicious ConnectI…
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-27483
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208246
|
6.1 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.
|
CWE-74
Injection
|
CVE-2020-27627
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208247
|
7.5 |
HIGH
Network
|
jetbrains
|
ideavim
|
JetBrains IdeaVim before version 0.58 might have caused an information leak in limited circumstances.
|
NVD-CWE-noinfo
|
CVE-2020-27623
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208248
|
5.3 |
MEDIUM
Network
|
jetbrains
|
intellij_idea
|
In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version.
|
NVD-CWE-noinfo
|
CVE-2020-27622
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208249
|
7.5 |
HIGH
Network
|
anuko
|
time_tracker
|
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-27423
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208250
|
9.8 |
CRITICAL
Network
|
anuko
|
time_tracker
|
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-27422
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|