|
212371
|
7.8 |
HIGH
Local
|
sun-denshi
|
universal_forensic_extraction_device_firmware
|
Cellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command prompt via the Windows file dialog that is reachable via the Certificate-Based…
|
CWE-269
Improper Privilege Management
|
CVE-2020-12798
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212372
|
9.8 |
CRITICAL
Network
|
eq-3
|
homematic_ccu2_firmware ccu3_firmware
|
eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the we…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-12834
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212373
|
6.1 |
MEDIUM
Network
|
redhat
|
interchange
|
XSS in the admin help system admin/help.html and admin/quicklinks.html in Interchange 4.7.0 through 5.11.x allows remote attackers to steal credentials or data via browser JavaScript.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12685
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212374
|
5.4 |
MEDIUM
Network
|
rcos
|
submitty
|
Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a Teaching Fellow.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12882
|
2024-11-21 14:00 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212375
|
7.5 |
HIGH
Network
|
veritas
|
aptare
|
Veritas APTARE versions prior to 10.4 allowed sensitive information to be accessible without authentication.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-12877
|
2024-11-21 14:00 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212376
|
7.5 |
HIGH
Network
|
veritas
|
aptare
|
Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulnerability only impacts Windows server deployments.
|
CWE-863
Incorrect Authorization
|
CVE-2020-12876
|
2024-11-21 14:00 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212377
|
6.3 |
MEDIUM
Network
|
veritas
|
aptare
|
Veritas APTARE versions prior to 10.4 did not perform adequate authorization checks. An authenticated user could gain unauthorized access to sensitive information or functionality by manipulating spe…
|
CWE-863
Incorrect Authorization
|
CVE-2020-12875
|
2024-11-21 14:00 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212378
|
9.8 |
CRITICAL
Network
|
veritas
|
aptare
|
Veritas APTARE versions prior to 10.4 included code that bypassed the normal login process when specific authentication credentials were provided to the server.
|
CWE-287
Improper Authentication
|
CVE-2020-12874
|
2024-11-21 14:00 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212379
|
6.1 |
MEDIUM
Network
|
progress
|
moveit_automation
|
An issue was discovered in Progress MOVEit Automation Web Admin. A Web Admin application endpoint failed to adequately sanitize malicious input, which could allow an unauthenticated attacker to execu…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12677
|
2024-11-21 14:00 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212380
|
6.5 |
MEDIUM
Adjacent
|
alberta tracetogether health gov
|
abtracetogether tracetogether covidsafe protego_safe
|
The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere with COVID-19 contact tracing, via a Bluetooth advertisement containing manufac…
|
NVD-CWE-noinfo
|
CVE-2020-12717
|
2024-11-21 14:00 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|