|
195901
|
8.3 |
HIGH
Network
|
openstack
|
manila
|
OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attack…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-9543
|
2024-11-21 14:40 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195902
|
7.5 |
HIGH
Network
|
beckhoff
|
bk9000_firmware
|
A Denial-of-Service vulnerability exists in BECKHOFF Ethernet TCP/IP Bus Coupler BK9000. After an attack has occurred, the device's functionality can be restored by rebooting.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-9464
|
2024-11-21 14:40 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195903
|
8.8 |
HIGH
Network
|
phoenixcontact
|
tc_router_3002t-4g_firmware tc_router_2002t-3g_firmware tc_router_3002t-4g_vzw_firmware tc_router_3002t-4g_att_firmware tc_cloud_client_1002-4g_firmware tc_cloud_client_1002-txtx_firmw…
|
PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.0…
|
CWE-78
OS Command
|
CVE-2020-9436
|
2024-11-21 14:40 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195904
|
7.5 |
HIGH
Network
|
phoenixcontact
|
tc_router_3002t-4g_firmware tc_router_2002t-3g_firmware tc_router_3002t-4g_vzw_firmware tc_router_3002t-4g_att_firmware tc_cloud_client_1002-4g_firmware tc_cloud_client_1002-txtx_firmw…
|
PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.0…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-9435
|
2024-11-21 14:40 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195905
|
8.8 |
HIGH
Network
|
tibco
|
spotfire_server spotfire_analytics_platform_for_aws
|
The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vulnerability that theoretically allows an attacker …
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-9408
|
2024-11-21 14:40 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195906
|
6.1 |
MEDIUM
Network
|
ckeditor webspellchecker fedoraproject
|
ckeditor webspellchecker fedora
|
A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML el…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9440
|
2024-11-21 14:40 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195907
|
5.4 |
MEDIUM
Network
|
microfocus
|
service_manager
|
There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60. The vulnerability may result in the ability of ma…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-9517
|
2024-11-21 14:40 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195908
|
4.3 |
MEDIUM
Network
|
mahara
|
mahara
|
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access…
|
CWE-200
Information Exposure
|
CVE-2020-9386
|
2024-11-21 14:40 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195909
|
6.5 |
MEDIUM
Network
|
mahara
|
mahara
|
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable inspecting network responses on the 'Edit access' screen when sharing port…
|
CWE-200
Information Exposure
|
CVE-2020-9282
|
2024-11-21 14:40 |
2020-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195910
|
7.8 |
HIGH
Local
|
wftpserver
|
wing_ftp_server
|
An issue was discovered in Wing FTP Server 6.2.5 before February 2020. Due to insecure permissions when handling session cookies, a local user may view the contents of the session and session_admin d…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-9470
|
2024-11-21 14:40 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|