|
208321
|
9.8 |
CRITICAL
Network
|
westerndigital
|
my_cloud_firmware
|
Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114 (issue 3 of 3).
|
CWE-22
Path Traversal
|
CVE-2020-27160
|
2024-11-21 14:20 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208322
|
9.8 |
CRITICAL
Network
|
westerndigital
|
my_cloud_firmware
|
Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western Digital My Cloud NAS devices prior to 5.04.114
|
CWE-78
OS Command
|
CVE-2020-27159
|
2024-11-21 14:20 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208323
|
9.8 |
CRITICAL
Network
|
westerndigital
|
my_cloud_firmware
|
Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114.
|
CWE-78
OS Command
|
CVE-2020-27158
|
2024-11-21 14:20 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208324
|
9.8 |
CRITICAL
Network
|
konzept-ix
|
publixone
|
A RemoteFunctions endpoint with missing access control in konzept-ix publiXone before 2020.015 allows attackers to disclose sensitive user information, send arbitrary e-mails, escalate the privileges…
|
NVD-CWE-noinfo
|
CVE-2020-27183
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208325
|
6.1 |
MEDIUM
Network
|
konzept-ix
|
publixone
|
Multiple cross-site scripting (XSS) vulnerabilities in konzept-ix publiXone before 2020.015 allow remote attackers to inject arbitrary JavaScript or HTML via appletError.jsp, job_jacket_detail.jsp, i…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27182
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208326
|
6.5 |
MEDIUM
Network
|
konzept-ix
|
publixone
|
A hardcoded AES key in CipherUtils.java in the Java applet of konzept-ix publiXone before 2020.015 allows attackers to craft password-reset tokens or decrypt server-side configuration files.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-27181
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208327
|
7.5 |
HIGH
Network
|
konzept-ix
|
publixone
|
konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-27180
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208328
|
9.8 |
CRITICAL
Network
|
konzept-ix
|
publixone
|
konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset tokens.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2020-27179
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208329
|
9.8 |
CRITICAL
Network
|
commscope
|
ruckus_vriot
|
Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorizat…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-26879
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208330
|
8.8 |
HIGH
Network
|
commscope
|
ruckus_vriot
|
Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be exe…
|
CWE-78
OS Command
|
CVE-2020-26878
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|