|
200931
|
7.8 |
HIGH
Local
|
westerndigital
|
dashboard
|
Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-29654
|
2024-11-21 14:24 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200932
|
9.8 |
CRITICAL
Network
|
westerndigital
|
my_cloud_os_5
|
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to gain access to the device.
|
CWE-287
Improper Authentication
|
CVE-2020-29563
|
2024-11-21 14:24 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200933
|
6.1 |
MEDIUM
Network
|
smartystreets
|
liveaddressplugin.js
|
A cross-Site Scripting (XSS) vulnerability in this.showInvalid and this.showInvalidCountry in SmartyStreets liveAddressPlugin.js 3.2 allows remote attackers to inject arbitrary web script or HTML via…
|
CWE-79
Cross-site Scripting
|
CVE-2020-29455
|
2024-11-21 14:24 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200934
|
9.8 |
CRITICAL
Network
|
sophos
|
cyberoamos
|
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
|
CWE-89
SQL Injection
|
CVE-2020-29574
|
2024-11-21 14:24 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200935
|
9.8 |
CRITICAL
Network
|
docker
|
registry
|
Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of the registry container may allow a remote attacke…
|
CWE-521
Weak Password Requirements
|
CVE-2020-29591
|
2024-11-21 14:24 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200936
|
9.8 |
CRITICAL
Network
|
lanatmservice
|
m3_atm_monitoring_system
|
In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient S…
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-29667
|
2024-11-21 14:24 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200937
|
5.3 |
MEDIUM
Network
|
lanatmservice
|
m3_atm_monitoring_system
|
In Lan ATMService M3 ATM Monitoring System 6.1.0, due to a directory-listing vulnerability, a remote attacker can view log files, located in /websocket/logs/, that contain a user's cookie values and …
|
NVD-CWE-Other
|
CVE-2020-29666
|
2024-11-21 14:24 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200938
|
3.7 |
LOW
Network
|
sympa fedoraproject debian
|
sympa fedora debian_linux
|
Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.
|
CWE-287 CWE-565
Improper Authentication Reliance on Cookies without Validation and Integrity Checking
|
CVE-2020-29668
|
2024-11-21 14:24 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200939
|
7.8 |
HIGH
Local
|
paloaltonetworks
|
cortex_xdr_agent
|
A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privil…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-2049
|
2024-11-21 14:24 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200940
|
5.5 |
MEDIUM
Local
|
paloaltonetworks
|
cortex_xdr_agent
|
An improper handling of exceptional conditions vulnerability in Cortex XDR Agent allows a local authenticated Windows user to create files in the software's internal program directory that prevents t…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-2020
|
2024-11-21 14:24 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|