|
196801
|
7.8 |
HIGH
Local
|
huawei
|
fusionaccess
|
FusionAccess version 6.5.1 has an improper authorization vulnerability. A command is authorized with incorrect privilege. Attackers with other privilege can execute the command to exploit this vulner…
|
NVD-CWE-noinfo
|
CVE-2020-9090
|
2024-11-21 14:40 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196802
|
6.7 |
MEDIUM
Local
|
huawei
|
taurus-an00b_firmware
|
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerabil…
|
CWE-20
Improper Input Validation
|
CVE-2020-9105
|
2024-11-21 14:40 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196803
|
7.5 |
HIGH
Network
|
apache
|
nifi
|
In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However i…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-9491
|
2024-11-21 14:40 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196804
|
7.5 |
HIGH
Network
|
apache
|
nifi
|
In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to create a download token, only when attempting to us…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-9487
|
2024-11-21 14:40 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196805
|
7.5 |
HIGH
Network
|
apache
|
nifi
|
In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON wa…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-9486
|
2024-11-21 14:40 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196806
|
5.4 |
MEDIUM
Network
|
tibco
|
spotfire_server spotfire_desktop spotfire_analytics_platform spotfire_analyst
|
The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, and TIBCO Spotfire Server contains a vuln…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9416
|
2024-11-21 14:40 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196807
|
5.5 |
MEDIUM
Local
|
huawei
|
bla-a09_firmware bla-tl00b_firmware berkeley-l09_firmware duke-l09_firmware p20_firmware p20_pro_firmware jimmy-al00a_firmware lon-l29d_firmware neo-al00d_firmware stanford…
|
Huawei smartphones BLA-A09 versions 8.0.0.123(C212),versions earlier than 8.0.0.123(C567),versions earlier than 8.0.0.123(C797);BLA-TL00B versions earlier than 8.1.0.326(C01);Berkeley-L09 versions ea…
|
CWE-20
Improper Input Validation
|
CVE-2020-9239
|
2024-11-21 14:40 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196808
|
6.8 |
MEDIUM
Adjacent
|
huawei
|
b2368-22_firmware b2368-57_firmware b2368-66_firmware
|
B2368-22 V100R001C00;B2368-57 V100R001C00;B2368-66 V100R001C00 have a command injection vulnerability. An attacker with high privileges may exploit this vulnerability through some operations on the L…
|
CWE-77
Command Injection
|
CVE-2020-9199
|
2024-11-21 14:40 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196809
|
5.5 |
MEDIUM
Local
|
huawei
|
honor_20_pro_firmware honor_view_20_firmware oxfords-an00a_firmware princeton-al10b_firmware princeton-al10d_firmware princeton-tl10c_firmware tony-al00b_firmware yale-al00a_firm…
|
Huawei smartphones HONOR 20 PRO Versions earlier than 10.1.0.230(C432E9R5P1),Versions earlier than 10.1.0.231(C10E3R3P2),Versions earlier than 10.1.0.231(C185E3R5P1),Versions earlier than 10.1.0.231(…
|
CWE-20
Improper Input Validation
|
CVE-2020-9235
|
2024-11-21 14:40 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196810
|
7.5 |
HIGH
Network
|
spinnaker
|
orca
|
The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-9298
|
2024-11-21 14:40 |
2020-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|