|
209511
|
6.5 |
MEDIUM
Network
|
spinetix
|
dsos hmp350_firmware hmp300_firmware diva_firmware hmp400_firmware hmp400w_firmware
|
spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP300, and DiVA through 4.5.2-1.0.36229; HMP400 and HM…
|
CWE-22 CWE-918
Path Traversal Server-Side Request Forgery (SSRF)
|
CVE-2020-15809
|
2024-11-21 14:06 |
2021-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209512
|
7.5 |
HIGH
Network
|
fortinet
|
fortios
|
When traffic other than HTTP/S (eg: SSH traffic, etc...) traverses the FortiGate in version below 6.2.5 and below 6.4.2 on port 80/443, it is not redirected to the transparent proxy policy for proces…
|
NVD-CWE-noinfo
|
CVE-2020-15938
|
2024-11-21 14:06 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209513
|
6.1 |
MEDIUM
Network
|
fortinet
|
fortios
|
An improper neutralization of input vulnerability in FortiGate version 6.2.x below 6.2.5 and 6.4.x below 6.4.1 may allow a remote attacker to perform a stored cross site scripting attack (XSS) via th…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15937
|
2024-11-21 14:06 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209514
|
4.4 |
MEDIUM
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
Overlayfs did not properly perform permission checking when copying up files in an overlayfs and could be exploited from within a user namespace, if, for example, unprivileged user namespaces were al…
|
NVD-CWE-Other
|
CVE-2020-16120
|
2024-11-21 14:06 |
2021-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209515
|
5.7 |
MEDIUM
Network
|
owncloud
|
files_antivirus
|
When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and another user uploads a virus the files antivirus app …
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-16144
|
2024-11-21 14:06 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209516
|
9.8 |
CRITICAL
Network
|
siemens
|
simatic_hmi_comfort_panels_firmware simatic_hmi_ktp_mobile_panels_firmware sinamics_gh150_firmware sinamics_gl150_firmware sinamics_gm150_firmware sinamics_sh150_firmware sinamics_s…
|
A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 3a), SINAMICS GH150 …
|
-
|
CVE-2020-15798
|
2024-11-21 14:06 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209517
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2020-16044
|
2024-11-21 14:06 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209518
|
5.3 |
MEDIUM
Network
|
store-opart
|
quote
|
An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to any user's invoice and delivery address by exploitin…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-16194
|
2024-11-21 14:06 |
2021-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209519
|
9.8 |
CRITICAL
Network
|
mofinetwork
|
mofi4500-4gxelte_firmware
|
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function passes untrusted data to the operating system without proper sanitization. A crafted request ca…
|
NVD-CWE-noinfo
|
CVE-2020-15836
|
2024-11-21 14:06 |
2021-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209520
|
9.8 |
CRITICAL
Network
|
mofinetwork
|
mofi4500-4gxelte_firmware
|
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocumented code that provides the ability to authenticate as root without knowing th…
|
CWE-287
Improper Authentication
|
CVE-2020-15835
|
2024-11-21 14:06 |
2021-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|