|
195821
|
5.9 |
MEDIUM
Network
|
tinxy
|
smart_wifi_door_lock_firmware
|
Tinxy Door Lock with firmware before 3.2 allow attackers to unlock a door by replaying an Unlock request that occurred when the attacker was previously authorized. In other words, door-access revocat…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2020-9438
|
2024-11-21 14:40 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195822
|
5.4 |
MEDIUM
Network
|
fortinet
|
fortiwlc
|
An improper neutralization of input vulnerability in FortiWLC 8.5.1 allows a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the ESS profile or the Radius Prof…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9288
|
2024-11-21 14:40 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195823
|
5.3 |
MEDIUM
Network
|
apache
|
archiva
|
Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute data from the connected LDAP server by providing special values to the login f…
|
CWE-74
Injection
|
CVE-2020-9495
|
2024-11-21 14:40 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195824
|
7.8 |
HIGH
Local
|
huawei
|
fusionsphere_openstack
|
FusionSphere OpenStack 6.5.1 have an improper permissions management vulnerability. The software does not correctly perform a privilege assignment when an actor attempts to perform an action. Success…
|
CWE-269
Improper Privilege Management
|
CVE-2020-9225
|
2024-11-21 14:40 |
2020-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195825
|
7.8 |
HIGH
Local
|
fabulatech
|
usb_for_remote_desktop
|
ftusbbus2.sys in FabulaTech USB for Remote Desktop through 2020-02-19 allows privilege escalation via crafted IoCtl code related to a USB HID device.
|
NVD-CWE-noinfo
|
CVE-2020-9332
|
2024-11-21 14:40 |
2020-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195826
|
7.5 |
HIGH
Network
|
fortinet
|
fortimanager fortianalyzer
|
Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access to the CLI configu…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-9289
|
2024-11-21 14:40 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195827
|
6.1 |
MEDIUM
Network
|
microfocus
|
arcsight_enterprise_security_manager_express
|
Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting versions 7.0.x, 7.2 and 7.2.1 . The vulnerabilities could be remotely exploited r…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9522
|
2024-11-21 14:40 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195828
|
9.8 |
CRITICAL
Network
|
netflix
|
conductor
|
Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are supported, including Jav…
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2020-9296
|
2024-11-21 14:40 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195829
|
5.0 |
MEDIUM
Network
|
open-xchange
|
ox_guard
|
OX Guard 2.10.3 and earlier allows SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-9427
|
2024-11-21 14:40 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195830
|
6.1 |
MEDIUM
Network
|
open-xchange
|
ox_guard
|
OX Guard 2.10.3 and earlier allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-9426
|
2024-11-21 14:40 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|