|
202721
|
8.8 |
HIGH
Network
|
grandstream
|
gwn7000_firmware
|
Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitra…
|
CWE-78
OS Command
|
CVE-2020-5756
|
2024-11-21 14:34 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202722
|
5.4 |
MEDIUM
Network
|
tenable
|
nessus
|
Nessus 8.10.0 and earlier were found to contain a Stored XSS vulnerability due to improper validation of input during scan configuration. An authenticated, remote attacker could potentially exploit t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5765
|
2024-11-21 14:34 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202723
|
7.5 |
HIGH
Network
|
dell
|
emc_omimssc_for_scvmm emc_omimssc_for_sccm
|
Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain a hard-coded cryptographic key vulnerability. A remote unauthenticated attacke…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-5374
|
2024-11-21 14:34 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202724
|
7.5 |
HIGH
Network
|
dell
|
emc_omimssc_for_scvmm emc_omimssc_for_sccm
|
Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain an improper authentication vulnerability. A remote unauthenticated attacker ma…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-5373
|
2024-11-21 14:34 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202725
|
7.5 |
HIGH
Network
|
srs_simple_hits_counter_project
|
srs_simple_hits_counter
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3 and 1.0.4 allows a remote, unauthenticated attacker to deter…
|
CWE-89
SQL Injection
|
CVE-2020-5766
|
2024-11-21 14:34 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202726
|
6.1 |
MEDIUM
Network
|
ss-proj
|
shirasagi
|
Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
|
CWE-601
Open Redirect
|
CVE-2020-5607
|
2024-11-21 14:34 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202727
|
6.5 |
MEDIUM
Network
|
dell
|
idrac9_firmware
|
Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability by manipula…
|
CWE-22
Path Traversal
|
CVE-2020-5366
|
2024-11-21 14:34 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202728
|
8.1 |
HIGH
Network
|
mercari
|
mercari
|
Android App 'Mercari' (Japan version) prior to version 3.52.0 allows arbitrary method execution of a Java object by a remote attacker via a Man-In-The-Middle attack by using Java Reflection API of Ja…
|
NVD-CWE-noinfo
|
CVE-2020-5604
|
2024-11-21 14:34 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202729
|
7.8 |
HIGH
Local
|
nvidia
|
jetpack_software_development_kit
|
NVIDIA JetPack SDK, version 4.2 and 4.3, contains a vulnerability in its installation scripts in which permissions are incorrectly set on certain directories, which can lead to escalation of privileg…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-5974
|
2024-11-21 14:34 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202730
|
7.5 |
HIGH
Network
|
symantec
|
endpoint_detection_and_response
|
Symantec Endpoint Detection And Response, prior to 4.4, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to dat…
|
NVD-CWE-noinfo
|
CVE-2020-5839
|
2024-11-21 14:34 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|