|
208121
|
9.8 |
CRITICAL
Network
|
ucms_project
|
ucms
|
An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-25483
|
2024-11-21 14:18 |
2020-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208122
|
9.8 |
CRITICAL
Network
|
crmeb
|
crmeb
|
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-25466
|
2024-11-21 14:18 |
2020-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208123
|
6.5 |
MEDIUM
Network
|
bigbluebutton
|
bigbluebutton
|
BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a crafted URL in an ODF xlink field.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-25820
|
2024-11-21 14:18 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208124
|
7.5 |
HIGH
Network
|
mozilla redhat fedoraproject oracle
|
network_security_services enterprise_linux fedora communications_offline_mediation_controller communications_pricing_design_center jd_edwards_enterpriseone_tools
|
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-25648
|
2024-11-21 14:18 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208125
|
7.5 |
HIGH
Network
|
qualcomm
|
qualcomm_mobile_access_point
|
The QCMAP_Web_CLIENT binary in the Qualcomm QCMAP software suite prior to versions released in October 2020 does not validate the return value of a strstr() or strchr() call in the Tokenizer() functi…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-25858
|
2024-11-21 14:18 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208126
|
7.5 |
HIGH
Network
|
powerdns opensuse
|
recursor leap backports_sle
|
An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSS…
|
NVD-CWE-noinfo
|
CVE-2020-25829
|
2024-11-21 14:18 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208127
|
6.7 |
MEDIUM
Local
|
qualcomm
|
qcmap
|
The QCMAP_CLI utility in the Qualcomm QCMAP software suite prior to versions released in October 2020 uses a system() call without validating the input, while handling a SetGatewayUrl() request. A lo…
|
CWE-78
OS Command
|
CVE-2020-25859
|
2024-11-21 14:18 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208128
|
2.4 |
LOW
Physics
|
telegram
|
telegram_desktop
|
Telegram Desktop through 2.4.3 does not require passcode entry upon pushing the Export key within the Export Telegram Data wizard. The threat model is a victim who has voluntarily opened Export Wizar…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-25824
|
2024-11-21 14:18 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208129
|
6.0 |
MEDIUM
Local
|
trendmicro
|
antivirus
|
Trend Micro Antivirus for Mac 2020 (Consumer) has a vulnerability in a specific kernel extension where an attacker could supply a kernel pointer and leak several bytes of memory. An attacker must fir…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-25778
|
2024-11-21 14:18 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208130
|
5.4 |
MEDIUM
Network
|
trendmicro
|
antivirus
|
Trend Micro Antivirus for Mac 2020 (Consumer) is vulnerable to a specific kernel extension request attack where an attacker could bypass the Web Threat Protection feature of the product. User interac…
|
NVD-CWE-noinfo
|
CVE-2020-25777
|
2024-11-21 14:18 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|