|
208011
|
9.8 |
CRITICAL
Network
|
emby
|
emby
|
Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-26948
|
2024-11-21 14:20 |
2020-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208012
|
7.8 |
HIGH
Local
|
getmonero
|
monero
|
monero-wallet-gui in Monero GUI before 0.17.1.0 includes the . directory in an embedded RPATH (with a preference ahead of /usr/lib), which allows local users to gain privileges via a Trojan horse lib…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-26947
|
2024-11-21 14:20 |
2020-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208013
|
8.1 |
HIGH
Network
|
mybatis
|
mybatis
|
MyBatis before 3.5.6 mishandles deserialization of object streams.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-26945
|
2024-11-21 14:20 |
2020-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208014
|
9.8 |
CRITICAL
Network
|
phpmyadmin opensuse fedoraproject debian
|
phpmyadmin leap backports_sle fedora debian_linux
|
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feat…
|
CWE-89
SQL Injection
|
CVE-2020-26935
|
2024-11-21 14:20 |
2020-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208015
|
6.1 |
MEDIUM
Network
|
phpmyadmin opensuse fedoraproject debian
|
phpmyadmin leap backports_sle fedora debian_linux
|
phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
|
CWE-79
Cross-site Scripting
|
CVE-2020-26934
|
2024-11-21 14:20 |
2020-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208016
|
4.3 |
MEDIUM
Network
|
sympa debian
|
sympa debian_linux
|
debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-26932
|
2024-11-21 14:20 |
2020-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208017
|
6.5 |
MEDIUM
Adjacent
|
netgear
|
wc7500_firmware wc7600_firmware wc9500_firmware
|
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects WC7500 before 6.5.5.24, WC7600 before 6.5.5.24, WC7600v2 before 6.5.5.24, and WC9500 before 6.5.5.24.
|
NVD-CWE-noinfo
|
CVE-2020-26931
|
2024-11-21 14:20 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208018
|
3.8 |
LOW
Network
|
netgear
|
ex7700_firmware
|
NETGEAR EX7700 devices before 1.0.0.210 are affected by incorrect configuration of security settings.
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2020-26930
|
2024-11-21 14:20 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208019
|
8.0 |
HIGH
Adjacent
|
netgear
|
r6230_firmware r6220_firmware
|
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100 and R6230 before 1.1.0.100.
|
CWE-77
Command Injection
|
CVE-2020-26929
|
2024-11-21 14:20 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208020
|
9.6 |
CRITICAL
Adjacent
|
netgear
|
cbr40_firmware rbk752_firmware rbk852_firmware rbr750_firmware rbr850_firmware rbs750_firmware rbs850_firmware
|
Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.10.11, …
|
NVD-CWE-noinfo
|
CVE-2020-26928
|
2024-11-21 14:20 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|