|
210061
|
7.5 |
HIGH
Network
|
evenroute
|
iqrouter_firmware
|
In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can onl…
|
CWE-287
Improper Authentication
|
CVE-2020-11964
|
2024-11-21 13:59 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210062
|
- |
|
-
|
-
|
AdvaBuild uses a command queue to launch certain operations. An attacker who gains access to the
command queue can use it to launch an attack by running any executable on the AdvaBuild node. The
exec…
|
-
|
CVE-2020-11640
|
2024-11-21 13:58 |
2024-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210063
|
- |
|
-
|
-
|
An attacker could exploit the vulnerability by
injecting garbage data or specially crafted data. Depending on the data injected each process might be
affected differently. The process could crash or …
|
-
|
CVE-2020-11639
|
2024-11-21 13:58 |
2024-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210064
|
6.5 |
MEDIUM
Network
|
netiq
|
access_manager
|
This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or before
|
NVD-CWE-noinfo
|
CVE-2020-11843
|
2024-11-21 13:58 |
2024-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210065
|
- |
|
-
|
-
|
Allocation of Resources Without Limits or Throttling vulnerability in OpenText NetIQ Privileged Account Manager on Linux, Windows, 64 bit allows Flooding.This issue affects NetIQ Privileged Account M…
|
-
|
CVE-2020-11862
|
2024-11-21 13:58 |
2024-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210066
|
4.8 |
MEDIUM
Network
|
stormshield
|
stormshield_network_security
|
An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded from the admin panel…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11711
|
2024-11-21 13:58 |
2023-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210067
|
5.5 |
MEDIUM
Local
|
canonical debian
|
ubuntu_linux debian_linux
|
It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerability to cause a denial of service attack.
|
NVD-CWE-Other
|
CVE-2020-11935
|
2024-11-21 13:58 |
2023-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210068
|
8.1 |
HIGH
Network
|
thimpress
|
learnpress
|
The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor via the accept-to-be-teacher action parameter.
|
CWE-862
Missing Authorization
|
CVE-2020-11511
|
2024-11-21 13:58 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210069
|
7.8 |
HIGH
Local
|
zscaler
|
client_connector
|
The Zscaler Client Connector for Windows prior to 2.1.2.105 had a DLL hijacking vulnerability caused due to the configuration of OpenSSL. A local adversary may be able to execute arbitrary code in th…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-11634
|
2024-11-21 13:58 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210070
|
7.8 |
HIGH
Local
|
zscaler
|
client_connector
|
The Zscaler Client Connector prior to 2.1.2.150 did not quote the search path for services, which allows a local adversary to execute code with system privileges.
|
CWE-428
Unquoted Search Path or Element
|
CVE-2020-11632
|
2024-11-21 13:58 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|