|
196221
|
9.8 |
CRITICAL
Network
|
belden
|
hirschmann_hios hirschmann_hisecos
|
A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could explo…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-6994
|
2024-11-21 14:36 |
2020-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196222
|
8.8 |
HIGH
Local
|
visam
|
vbase_web-remote vbase_editor
|
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow weak or insecure permissions on the VBASE directory resulting in elevation of privileges or malicious effects on the system t…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-7004
|
2024-11-21 14:36 |
2020-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196223
|
7.5 |
HIGH
Network
|
visam
|
vbase_web-remote vbase_editor
|
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow an unauthenticated attacker to discover the cryptographic key from the web server and gain information about the login and th…
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2020-7000
|
2024-11-21 14:36 |
2020-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196224
|
9.8 |
CRITICAL
Network
|
cacagoo
|
tv-288zd-2mp_firmware
|
CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root privileges without any password required.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-6852
|
2024-11-21 14:36 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196225
|
6.1 |
MEDIUM
Network
|
auth0
|
login_by_auth0
|
The Login by Auth0 plugin before 4.0.0 for WordPress allows stored XSS on multiple pages, a different issue than CVE-2020-5392.
|
CWE-79
Cross-site Scripting
|
CVE-2020-6753
|
2024-11-21 14:36 |
2020-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196226
|
6.7 |
MEDIUM
Local
|
mcafee
|
endpoint_security
|
Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current versions allows local administrator to alter ENS configuration up to and including …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-7263
|
2024-11-21 14:36 |
2020-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196227
|
4.3 |
MEDIUM
Network
|
php tenable opensuse debian
|
php tenable.sc leap debian_linux
|
In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently trunc…
|
NVD-CWE-Other
|
CVE-2020-7066
|
2024-11-21 14:36 |
2020-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196228
|
8.8 |
HIGH
Network
|
php debian canonical tenable
|
php debian_linux ubuntu_linux tenable.sc
|
In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. Thi…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7065
|
2024-11-21 14:36 |
2020-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196229
|
5.4 |
MEDIUM
Network
|
php debian canonical opensuse tenable
|
php debian_linux ubuntu_linux leap tenable.sc
|
In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data with exif_read_data() function, it is possible for malicious data to cause PHP to read one byte of…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-7064
|
2024-11-21 14:36 |
2020-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196230
|
8.8 |
HIGH
Network
|
elastic
|
elasticsearch
|
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can…
|
CWE-269
Improper Privilege Management
|
CVE-2020-7009
|
2024-11-21 14:36 |
2020-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|