|
196451
|
9.8 |
CRITICAL
Network
|
phplist
|
phplist
|
phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical character…
|
NVD-CWE-noinfo
|
CVE-2020-8547
|
2024-11-21 14:39 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196452
|
7.5 |
HIGH
Network
|
circl
|
ail_framework
|
Global.py in AIL framework 2.8 allows path traversal.
|
CWE-22
Path Traversal
|
CVE-2020-8545
|
2024-11-21 14:39 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196453
|
- |
|
-
|
-
|
The server in Circontrol Raption through 5.11.2 has a pre-authentication stack-based buffer overflow that can be exploited to gain run-time control of the device as root. The ocpp1.5 and pwrstudio bi…
|
-
|
CVE-2020-8006
|
2024-11-21 14:38 |
2024-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196454
|
7.2 |
HIGH
Network
|
expressionengine
|
expressionengine
|
Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user needs member creation/admin control panel access to execute the attack.
|
CWE-89
SQL Injection
|
CVE-2020-8242
|
2024-11-21 14:38 |
2022-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196455
|
7.8 |
HIGH
Local
|
bitdefender
|
total_security internet_security antivirus_plus
|
A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper with product settings via a specially crafted DLL file. This issue affects: Bi…
|
NVD-CWE-Other
|
CVE-2020-8107
|
2024-11-21 14:38 |
2022-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196456
|
7.8 |
HIGH
Local
|
goabode
|
iota_all-in-one_security_kit_firmware
|
OS Command Injection vulnerability in the wirelessConnect handler of Abode iota All-In-One Security Kit allows an attacker to inject commands and gain root access. This issue affects: Abode iota All-…
|
CWE-78
OS Command
|
CVE-2020-8105
|
2024-11-21 14:38 |
2021-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196457
|
6.1 |
MEDIUM
Network
|
rocket.chat
|
rocket.chat
|
A link preview rendering issue in Rocket.Chat versions before 3.9 could lead to potential XSS attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8291
|
2024-11-21 14:38 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196458
|
6.5 |
MEDIUM
Network
|
citrix
|
netscaler_gateway gateway application_delivery_controller_firmware
|
Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack t…
|
NVD-CWE-Other
|
CVE-2020-8300
|
2024-11-21 14:38 |
2021-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196459
|
6.5 |
MEDIUM
Adjacent
|
citrix
|
netscaler_gateway gateway application_delivery_controller_firmware sd-wan_wanop
|
Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-8299
|
2024-11-21 14:38 |
2021-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196460
|
6.5 |
MEDIUM
Network
|
mongodb
|
mongomirror database_tools
|
Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping all certificate validation. This may result in acc…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-7924
|
2024-11-21 14:38 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|