|
208281
|
9.8 |
CRITICAL
Network
|
hazelcast
|
hazelcast jet
|
The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenar…
|
CWE-287
Improper Authentication
|
CVE-2020-26168
|
2024-11-21 14:19 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208282
|
6.5 |
MEDIUM
Network
|
cisco
|
edge_fog_fabric
|
A vulnerability in the REST API of Cisco Edge Fog Fabric could allow an authenticated, remote attacker to access files outside of their authorization sphere on an affected device. The vulnerability i…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-26084
|
2024-11-21 14:19 |
2020-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208283
|
7.5 |
HIGH
Network
|
teler_project
|
teler
|
In teler before version 0.0.1, if you run teler inside a Docker container and encounter `errors.Exit` function, it will cause denial-of-service (`SIGSEGV`) because it doesn't get process ID and proce…
|
-
|
CVE-2020-26213
|
2024-11-21 14:19 |
2020-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208284
|
4.3 |
MEDIUM
Network
|
cisco
|
telepresence_collaboration_endpoint
|
A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, remote attacker to gain access to sensitive information on an…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-26086
|
2024-11-21 14:19 |
2020-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208285
|
4.8 |
MEDIUM
Network
|
cisco
|
identity_services_engine
|
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scr…
|
CWE-79
Cross-site Scripting
|
CVE-2020-26083
|
2024-11-21 14:19 |
2020-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208286
|
9.8 |
CRITICAL
Network
|
alerta_project
|
alerta
|
In Alerta before version 8.1.0, users may be able to bypass LDAP authentication if they provide an empty password when Alerta server is configure to use LDAP as the authorization provider. Only deplo…
|
-
|
CVE-2020-26214
|
2024-11-21 14:19 |
2020-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208287
|
7.5 |
HIGH
Network
|
linuxfoundation fedoraproject
|
nats-server fedora
|
The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code).
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-26521
|
2024-11-21 14:19 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208288
|
7.8 |
HIGH
Local
|
marmind
|
marmind
|
A CSV Injection (also known as Formula Injection) vulnerability in the Marmind web application with version 4.1.141.0 allows malicious users to gain remote control of other computers. By providing fo…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-26507
|
2024-11-21 14:19 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208289
|
6.1 |
MEDIUM
Network
|
marmind
|
marmind
|
A Stored Cross-Site Scripting (XSS) vulnerability in the “Marmind” web application with version 4.1.141.0 allows an attacker to inject code that will later be executed by legitimate users when they o…
|
CWE-79
Cross-site Scripting
|
CVE-2020-26505
|
2024-11-21 14:19 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208290
|
4.3 |
MEDIUM
Network
|
marmind
|
marmind
|
An Authorization Bypass vulnerability in the Marmind web application with version 4.1.141.0 allows users with lower privileges to gain control to files uploaded by administrative users. The accessed …
|
CWE-670 CWE-863
Always-Incorrect Control Flow Implementation Incorrect Authorization
|
CVE-2020-26506
|
2024-11-21 14:19 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|