|
196871
|
7.5 |
HIGH
Network
|
zte
|
zxhn_e8810_firmware zxhn_e8820_firmware zxhn_e8822_firmware
|
ZTE E8810/E8820/E8822 series routers have an MQTT DoS vulnerability, which is caused by the failure of the device to verify the validity of abnormal messages. A remote attacker could connect to the M…
|
CWE-346
Origin Validation Error
|
CVE-2020-6881
|
2024-11-21 14:36 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196872
|
9.8 |
CRITICAL
Network
|
hp
|
ilo_amplifier_pack
|
A potential security vulnerability has been identified in HPE iLO Amplifier Pack server version 1.70. The vulnerability could be exploited to allow remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-7203
|
2024-11-21 14:36 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196873
|
8.8 |
HIGH
Network
|
hp
|
storeever_msl2024_firmware storeever_1\/8_g2_tape_autoloader_firmware
|
A potential security vulnerability has been identified in the HPE StoreEver MSL2024 Tape Library and HPE StoreEver 1/8 G2 Tape Autoloaders. The vulnerability could be remotely exploited to allow Cros…
|
CWE-352
Origin Validation Error
|
CVE-2020-7201
|
2024-11-21 14:36 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196874
|
9.8 |
CRITICAL
Network
|
hp
|
systems_insight_manager
|
A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerability could be exploited to allow remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-7200
|
2024-11-21 14:36 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196875
|
9.8 |
CRITICAL
Network
|
hp
|
edgeline_infrastructure_manager
|
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited t…
|
CWE-287
Improper Authentication
|
CVE-2020-7199
|
2024-11-21 14:36 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196876
|
9.8 |
CRITICAL
Network
|
zte
|
zxv10_w908_firmware
|
A ZXELINK wireless controller has a SQL injection vulnerability. A remote attacker does not need to log in. By sending malicious SQL statements, because the device does not properly filter parameters…
|
CWE-89
SQL Injection
|
CVE-2020-6880
|
2024-11-21 14:36 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196877
|
9.8 |
CRITICAL
Network
|
tableau
|
tableau_server
|
Tableau Server installations configured with Site-Specific SAML that allows the APIs to be used by unauthenticated users. If exploited, this could allow a malicious user to configure Site-Specific SA…
|
NVD-CWE-noinfo
|
CVE-2020-6939
|
2024-11-21 14:36 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196878
|
3.5 |
LOW
Adjacent
|
zte
|
zxhn_z500_firmware zxhn_f670l_firmware
|
Some ZTE devices have input verification vulnerabilities. The devices support configuring a static prefix through the web management page. The restriction of the front-end code can be bypassed by con…
|
CWE-20
Improper Input Validation
|
CVE-2020-6879
|
2024-11-21 14:36 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196879
|
6.5 |
MEDIUM
Network
|
avaya
|
aura_system_manager weblm
|
An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in…
|
CWE-611
XXE
|
CVE-2020-7032
|
2024-11-21 14:36 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196880
|
5.4 |
MEDIUM
Network
|
avaya
|
equinox_conferencing
|
A Cross Site Scripting (XSS) Vulnerability on the Unified Portal Client (web client) used in Avaya Equinox Conferencing can allow an authenticated user to perform XSS attacks. The affected versions o…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7033
|
2024-11-21 14:36 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|