|
208131
|
9.8 |
CRITICAL
Network
|
konzept-ix
|
publixone
|
A RemoteFunctions endpoint with missing access control in konzept-ix publiXone before 2020.015 allows attackers to disclose sensitive user information, send arbitrary e-mails, escalate the privileges…
|
NVD-CWE-noinfo
|
CVE-2020-27183
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208132
|
6.1 |
MEDIUM
Network
|
konzept-ix
|
publixone
|
Multiple cross-site scripting (XSS) vulnerabilities in konzept-ix publiXone before 2020.015 allow remote attackers to inject arbitrary JavaScript or HTML via appletError.jsp, job_jacket_detail.jsp, i…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27182
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208133
|
6.5 |
MEDIUM
Network
|
konzept-ix
|
publixone
|
A hardcoded AES key in CipherUtils.java in the Java applet of konzept-ix publiXone before 2020.015 allows attackers to craft password-reset tokens or decrypt server-side configuration files.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-27181
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208134
|
7.5 |
HIGH
Network
|
konzept-ix
|
publixone
|
konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-27180
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208135
|
9.8 |
CRITICAL
Network
|
konzept-ix
|
publixone
|
konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset tokens.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2020-27179
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208136
|
9.8 |
CRITICAL
Network
|
commscope
|
ruckus_vriot
|
Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorizat…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-26879
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208137
|
8.8 |
HIGH
Network
|
commscope
|
ruckus_vriot
|
Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be exe…
|
CWE-78
OS Command
|
CVE-2020-26878
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208138
|
7.5 |
HIGH
Network
|
motion_project
|
motion
|
A Denial of Service condition in Motion-Project Motion 3.2 through 4.3.1 allows remote unauthenticated users to cause a webu.c segmentation fault and kill the main process via a crafted HTTP request.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-26566
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208139
|
7.8 |
HIGH
Local
|
kde
|
partition_manager
|
An issue was discovered in KDE Partition Manager 4.1.0 before 4.2.0. The kpmcore_externalcommand helper contains a logic flaw in which the service invoking D-Bus is not properly checked. An attacker …
|
NVD-CWE-noinfo
|
CVE-2020-27187
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208140
|
7.0 |
HIGH
Local
|
eclipse netapp oracle apache debian
|
jetty snap_creator_framework snapcenter vasa_provider virtual_storage_console storage_replication_adapter flexcube_private_banking communications_offline_mediation_controller …
|
In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between al…
|
NVD-CWE-Other
|
CVE-2020-27216
|
2024-11-21 14:20 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|