|
208681
|
9.6 |
CRITICAL
Network
|
free
|
freebox_revolution_firmware freebox_mini_firmware freebox_one_firmware freebox_delta_firmware freebox_pop_firmware
|
A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2.3.
|
CWE-20
Improper Input Validation
|
CVE-2020-24376
|
2024-11-21 14:14 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208682
|
9.6 |
CRITICAL
Network
|
free
|
freebox_hd_firmware
|
A DNS rebinding vulnerability in Freebox v5 before 1.5.29.
|
CWE-20
Improper Input Validation
|
CVE-2020-24374
|
2024-11-21 14:14 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208683
|
8.8 |
HIGH
Network
|
free
|
freebox_revolution_firmware freebox_mini_firmware freebox_one_firmware freebox_delta_firmware freebox_pop_firmware
|
A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.
|
CWE-352
Origin Validation Error
|
CVE-2020-24373
|
2024-11-21 14:14 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208684
|
9.8 |
CRITICAL
Network
|
projectworlds
|
house_rental
|
Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute arbitrary code on the hosting webserver via a malicious index.php POS…
|
CWE-89
SQL Injection
|
CVE-2020-23833
|
2024-11-21 14:14 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208685
|
9.8 |
CRITICAL
Network
|
online_course_registration_project
|
online_course_registration
|
A File Upload vulnerability in SourceCodester Online Course Registration v1.0 allows remote attackers to achieve Remote Code Execution (RCE) on the hosting webserver by uploading a crafted PHP web-sh…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-23828
|
2024-11-21 14:14 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208686
|
9.1 |
CRITICAL
Network
|
trendmicro
|
serverprotect
|
A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrary code on an affected system. An attacker must first obtain admin/root privileg…
|
CWE-77
Command Injection
|
CVE-2020-24561
|
2024-11-21 14:14 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208687
|
7.6 |
HIGH
Physics
|
intel
|
core_i7-8665ue_firmware core_i7-8665u_firmware core_i7-8557u_firmware core_i7-8850h_firmware core_i7-8809g_firmware core_i7-8750h_firmware core_i7-8709g_firmware core_i7-8706g_fi…
|
Logic error in BIOS firmware for 8th, 9th and 10th Generation Intel(R) Core(TM) Processors may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or in…
|
NVD-CWE-noinfo
|
CVE-2020-24457
|
2024-11-21 14:14 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208688
|
8.8 |
HIGH
Network
|
argosoft
|
mail_server
|
ArGo Soft Mail Server 1.8.8.9 is affected by Cross Site Request Forgery (CSRF) for perform remote arbitrary code execution. The component is the Administration dashboard. When using admin/user creden…
|
CWE-352
Origin Validation Error
|
CVE-2020-23824
|
2024-11-21 14:14 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208689
|
7.8 |
HIGH
Local
|
taoensso
|
nippy
|
A deserialization flaw is present in Taoensso Nippy before 2.14.2. In some circumstances, it is possible for an attacker to create a malicious payload that, when deserialized, will allow arbitrary co…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-24164
|
2024-11-21 14:14 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208690
|
7.2 |
HIGH
Network
|
atoptechnology
|
se5901_firmware se5901b_firmware se5904d_firmware se5908_firmware se5908a_firmware se5916_firmware se5916a_firmware
|
Atop Technology industrial 3G/4G gateway contains Command Injection vulnerability. Due to insufficient input validation, the device's web management interface allows attackers to inject specific code…
|
CWE-78
OS Command
|
CVE-2020-24552
|
2024-11-21 14:14 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|