|
208161
|
8.8 |
HIGH
Adjacent
|
netgear
|
rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware
|
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.…
|
CWE-77
Command Injection
|
CVE-2020-26902
|
2024-11-21 14:20 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208162
|
6.5 |
MEDIUM
Adjacent
|
netgear
|
rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware
|
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.25, RBR850 be…
|
NVD-CWE-noinfo
|
CVE-2020-26901
|
2024-11-21 14:20 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208163
|
8.8 |
HIGH
Adjacent
|
netgear
|
cbr40_firmware rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware
|
Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852…
|
NVD-CWE-noinfo
|
CVE-2020-26900
|
2024-11-21 14:20 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208164
|
6.5 |
MEDIUM
Adjacent
|
netgear
|
cbr40_firmware rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware
|
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 befo…
|
NVD-CWE-noinfo
|
CVE-2020-26899
|
2024-11-21 14:20 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208165
|
8.8 |
HIGH
Adjacent
|
netgear
|
rax40_firmware
|
NETGEAR RAX40 devices before 1.0.3.80 are affected by incorrect configuration of security settings.
|
NVD-CWE-Other
|
CVE-2020-26898
|
2024-11-21 14:20 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208166
|
8.8 |
HIGH
Adjacent
|
netgear
|
cbr40_firmware rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware
|
Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852…
|
NVD-CWE-noinfo
|
CVE-2020-26897
|
2024-11-21 14:20 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208167
|
8.8 |
HIGH
Network
|
garfield_petshop_project
|
garfield_petshop
|
A cross-site request forgery (CSRF) vulnerability in mod/user/act_user.php in Garfield Petshop through 2020-10-01 allows remote attackers to hijack the authentication of administrators for requests t…
|
CWE-352
Origin Validation Error
|
CVE-2020-26522
|
2024-11-21 14:20 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208168
|
7.8 |
HIGH
Local
|
faulknermedia
|
wildlife_issues_in_the_new_millennium
|
LiveCode v9.6.1 on Windows allows local, low-privileged users to gain privileges by creating a malicious "cmd.exe" in the folder of the vulnerable LiveCode application. If the application is using Li…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-26894
|
2024-11-21 14:20 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208169
|
8.8 |
HIGH
Network
|
formalms
|
formalms
|
forma.lms 2.3.0.2 is affected by Cross Site Request Forgery (CSRF) in formalms/appCore/index.php?r=lms/profile/show&ap=saveinfo via a GET request to change the admin email address in order to accompl…
|
CWE-352
Origin Validation Error
|
CVE-2020-26802
|
2024-11-21 14:20 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208170
|
5.5 |
MEDIUM
Local
|
dlink
|
dsr-250n_firmware
|
An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any access reboots the device, rendering it therefore u…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-26567
|
2024-11-21 14:20 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|