|
209661
|
6.1 |
MEDIUM
Network
|
vivo
|
appstore
|
The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps through carefully constructed parameters.
|
CWE-601
Open Redirect
|
CVE-2020-12483
|
2024-11-21 13:59 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209662
|
6.1 |
MEDIUM
Network
|
mbconnectline
|
mbconnect24 mymbconnect24
|
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. There is an XSS issue in the redirect.php allowing an attacker to inject code via a g…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12530
|
2024-11-21 13:59 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209663
|
5.3 |
MEDIUM
Network
|
mbconnectline
|
mbconnect24 mymbconnect24
|
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There is a SSRF in the LDAP access check, allowing an attacker to scan for open ports.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-12529
|
2024-11-21 13:59 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209664
|
7.7 |
HIGH
Network
|
mbconnectline
|
mbconnect24 mymbconnect24
|
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access validation allows a logged in user to kill web2go sessions in …
|
CWE-269
Improper Privilege Management
|
CVE-2020-12528
|
2024-11-21 13:59 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209665
|
6.5 |
MEDIUM
Network
|
mbconnectline helmholz
|
mbconnect24 mymbconnect24 myrex24.virtual myrex24
|
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to s…
|
-
|
CVE-2020-12527
|
2024-11-21 13:59 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209666
|
8.2 |
HIGH
Network
|
apache fedoraproject
|
xmlgraphics_commons fedora
|
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could…
|
CWE-20 CWE-918
Improper Input Validation Server-Side Request Forgery (SSRF)
|
CVE-2020-11988
|
2024-11-21 13:59 |
2021-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209667
|
8.2 |
HIGH
Network
|
apache fedoraproject oracle debian
|
batik fedora enterprise_repository retail_back_office weblogic_server retail_order_broker retail_returns_management retail_central_office retail_point-of-service instantis_…
|
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulne…
|
CWE-20 CWE-918
Improper Input Validation Server-Side Request Forgery (SSRF)
|
CVE-2020-11987
|
2024-11-21 13:59 |
2021-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209668
|
6.7 |
MEDIUM
Local
|
intel
|
bmc_firmware
|
Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow a privileged user to potentially enable escalation of privilege v…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-12374
|
2024-11-21 13:59 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209669
|
5.5 |
MEDIUM
Local
|
intel
|
graphics_drivers
|
Untrusted pointer dereference in some Intel(R) Graphics Drivers before versions 15.33.51.5146, 15.45.32.5145, 15.36.39.5144 and 15.40.46.5143 may allow an authenticated user to potentially denial of …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-12365
|
2024-11-21 13:59 |
2021-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209670
|
5.5 |
MEDIUM
Local
|
intel
|
graphics_drivers
|
Out-of-bounds write in some Intel(R) Graphics Drivers before version 15.36.39.5143 may allow an authenticated user to potentially enable denial of service via local access.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12386
|
2024-11-21 13:59 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|