|
196231
|
7.5 |
HIGH
Network
|
citrix
|
sharefile_storagezones_controller
|
An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020. RCE and …
|
CWE-22
Path Traversal
|
CVE-2020-8982
|
2024-11-21 14:39 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196232
|
9.8 |
CRITICAL
Network
|
google
|
android
|
There is a buffer overwrite vulnerability in the Quram qmg library of Samsung's Android OS versions O(8.x), P(9.0) and Q(10.0). An unauthenticated, unauthorized attacker sending a specially crafted M…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-8899
|
2024-11-21 14:39 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196233
|
8.8 |
HIGH
Network
|
commscope
|
ruckus_zoneflex_r500_firmware
|
CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen.
|
CWE-352 CWE-918
Origin Validation Error Server-Side Request Forgery (SSRF)
|
CVE-2020-8830
|
2024-11-21 14:39 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196234
|
8.8 |
HIGH
Network
|
intelbras
|
cip_92200_firmware
|
CSRF on Intelbras CIP 92200 devices allows an attacker to access the panel and perform scraping or other analysis.
|
CWE-352
Origin Validation Error
|
CVE-2020-8829
|
2024-11-21 14:39 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196235
|
4.8 |
MEDIUM
Network
|
webtechideas
|
wti_like_post
|
A Stored XSS vulnerability has been found in the administration page of the WTI Like Post plugin through 1.4.5 for WordPress. Once the administrator has submitted the data, the script stored is execu…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8799
|
2024-11-21 14:39 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196236
|
5.9 |
MEDIUM
Network
|
google
|
earth
|
A Buffer Overflow vulnerability in the khcrypt implementation in Google Earth Pro versions up to and including 7.3.2 allows an attacker to perform a Man-in-the-Middle attack using a specially crafted…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-8896
|
2024-11-21 14:39 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196237
|
5.3 |
MEDIUM
Network
|
oklok_project
|
oklok
|
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has an information-exposure issue. In the mobile app, an attempt to add an already-bound lock by its barcode reveal…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-8792
|
2024-11-21 14:39 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196238
|
6.5 |
MEDIUM
Network
|
oklok_project
|
oklok
|
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) allows remote attackers to submit API requests using authenticated but unauthorized tokens, resulting in IDOR issue…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-8791
|
2024-11-21 14:39 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196239
|
9.8 |
CRITICAL
Network
|
oklok_project
|
oklok
|
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could…
|
CWE-307 CWE-521
mproper Restriction of Excessive Authentication Attempts Weak Password Requirements
|
CVE-2020-8790
|
2024-11-21 14:39 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196240
|
8.9 |
HIGH
Network
|
pega
|
platform
|
Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8775
|
2024-11-21 14:39 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|