|
208141
|
8.8 |
HIGH
Network
|
belkin
|
linksys_wrt_160nl_firmware
|
Belkin LINKSYS WRT160NL 1.0.04.002_US_20130619 devices have a stack-based buffer overflow vulnerability because of sprintf in create_dir in mini_httpd. Successful exploitation leads to arbitrary code…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-26561
|
2024-11-21 14:20 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208142
|
7.8 |
HIGH
Local
|
avm
|
fritz\!box_7490_firmware
|
FRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism.
|
NVD-CWE-noinfo
|
CVE-2020-26887
|
2024-11-21 14:20 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208143
|
9.1 |
CRITICAL
Network
|
hashicorp
|
nomad
|
HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6
|
NVD-CWE-noinfo
|
CVE-2020-27195
|
2024-11-21 14:20 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208144
|
7.5 |
HIGH
Network
|
octopus
|
octopus_deploy
|
An issue was discovered in Octopus Deploy through 2020.4.4. If enabled, the websocket endpoint may allow an untrusted tentacle host to present itself as a trusted one.
|
NVD-CWE-noinfo
|
CVE-2020-27155
|
2024-11-21 14:20 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208145
|
5.3 |
MEDIUM
Network
|
atomx
|
atomxcms
|
AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php
|
CWE-22 CWE-668
Path Traversal Exposure of Resource to Wrong Sphere
|
CVE-2020-26650
|
2024-11-21 14:20 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208146
|
8.1 |
HIGH
Network
|
atomx
|
atomxcms_2
|
AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php
|
CWE-306 CWE-862
Missing Authentication for Critical Function Missing Authorization
|
CVE-2020-26649
|
2024-11-21 14:20 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208147
|
5.3 |
MEDIUM
Network
|
lightning_network_daemon_project
|
lightning_network_daemon
|
Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast tx-relay invalid local commitment/HTLC transactions. This can be exploited by an…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-26895
|
2024-11-21 14:20 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208148
|
6.1 |
MEDIUM
Network
|
matrix
|
synapse
|
AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET parameter. This allows a remote attacker to execute an XSS attack on the domain Syn…
|
CWE-79
Cross-site Scripting
|
CVE-2020-26891
|
2024-11-21 14:20 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208149
|
9.8 |
CRITICAL
Network
|
libtaxii_project eclecticiq
|
libtaxii opentaxii
|
TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-27197
|
2024-11-21 14:20 |
2020-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208150
|
8.2 |
HIGH
Network
|
lightning_network_daemon_project
|
lightning_network_daemon
|
Prior to 0.11.0-beta, LND (Lightning Network Daemon) had a vulnerability in its invoice database. While claiming on-chain a received HTLC output, it didn't verify that the corresponding outgoing off-…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-26896
|
2024-11-21 14:20 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|