|
196191
|
6.8 |
MEDIUM
Network
|
kubernetes
|
kubernetes
|
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an att…
|
CWE-601
Open Redirect
|
CVE-2020-8559
|
2024-11-21 14:39 |
2020-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196192
|
7.2 |
HIGH
Network
|
gpononu
|
1ge_router_wifi_onu_v2801rw_firmware 1ge\+3fe\+wifi_onu_v2804rgw_firmware
|
Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in …
|
CWE-78
OS Command
|
CVE-2020-8958
|
2024-11-21 14:39 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196193
|
5.5 |
MEDIUM
Local
|
openthread
|
wpantund
|
A memory leak in Openthread's wpantund versions up to commit 0e5d1601febb869f583e944785e5685c6c747be7, when used in an environment where wpanctl is directly interfacing with the control driver (eg: d…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-8916
|
2024-11-21 14:39 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196194
|
7.5 |
HIGH
Network
|
envoyproxy
|
envoy
|
Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and/or memory when accepting too many connections.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-8663
|
2024-11-21 14:39 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196195
|
6.5 |
MEDIUM
Network
|
netapp
|
hci_h610s_firmware
|
The NetApp HCI H610C, H615C and H610S Baseboard Management Controllers (BMC) are shipped with a documented default account and password that should be changed during the initial node setup. During up…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-8573
|
2024-11-21 14:39 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196196
|
7.2 |
HIGH
Network
|
johnsoncontrols
|
exacqvision_web_service exacqvision_enterprise_manager
|
A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterpr…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-9047
|
2024-11-21 14:39 |
2020-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196197
|
7.8 |
HIGH
Local
|
google opensuse
|
guest-oslogin leap
|
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Usi…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-8933
|
2024-11-21 14:39 |
2020-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196198
|
7.8 |
HIGH
Local
|
google opensuse
|
guest-oslogin leap
|
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Usi…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-8907
|
2024-11-21 14:39 |
2020-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196199
|
7.8 |
HIGH
Local
|
google opensuse
|
guest-oslogin leap
|
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Usi…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-8903
|
2024-11-21 14:39 |
2020-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196200
|
4.9 |
MEDIUM
Network
|
isc opensuse netapp canonical
|
bind leap steelstore_cloud_integrated_storage ubuntu_linux
|
An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clie…
|
CWE-617
Reachable Assertion
|
CVE-2020-8618
|
2024-11-21 14:39 |
2020-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|