|
209141
|
5.5 |
MEDIUM
Local
|
trustedcomputinggroup fedoraproject
|
trousers fedora
|
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to c…
|
CWE-59
Link Following
|
CVE-2020-24332
|
2024-11-21 14:14 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209142
|
7.8 |
HIGH
Local
|
trousers_project fedoraproject
|
trousers fedora
|
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access to the /etc/tcsd.conf file (which contains various…
|
CWE-269
Improper Privilege Management
|
CVE-2020-24331
|
2024-11-21 14:14 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209143
|
7.8 |
HIGH
Local
|
trousers_project fedoraproject
|
trousers fedora
|
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop the root gid privilege when no longer needed.
|
CWE-269
Improper Privilege Management
|
CVE-2020-24330
|
2024-11-21 14:14 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209144
|
7.8 |
HIGH
Local
|
flac_project
|
flac
|
Buffer Overflow vulnerability in function bitwriter_grow_ in flac before 1.4.0 allows remote attackers to run arbitrary code via crafted input to the encoder.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-22219
|
2024-11-21 14:13 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209145
|
8.8 |
HIGH
Network
|
evertz
|
3080ipx_firmware 7801fc_firmware 7890ixg_firmware
|
EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upload, allowing an authenticated attacker to upload a webshell or overwrite any c…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-22159
|
2024-11-21 14:13 |
2023-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209146
|
8.8 |
HIGH
Network
|
verydows
|
verydows
|
Cross Site Request Forgery (CSRF) vulnerability found in Verytops Verydows all versions that allows an attacker to execute arbitrary code via a crafted script.
|
CWE-352
Origin Validation Error
|
CVE-2020-23363
|
2024-11-21 14:13 |
2023-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209147
|
9.8 |
CRITICAL
Network
|
ruckuswireless
|
r310_firmware r500_firmware r600_firmware t300_firmware t301n_firmware t301s_firmware scg200_firmware sz-100_firmware sz-300_firmware vsz_firmware zonedirector_1100_firm…
|
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before …
|
NVD-CWE-noinfo
|
CVE-2020-22654
|
2024-11-21 14:13 |
2023-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209148
|
6.5 |
MEDIUM
Network
|
optilinknetwork
|
op-xt71000n_firmware
|
A vulnerability in the "/admin/wlmultipleap.asp" of optilink OP-XT71000N version: V2.2 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to create …
|
CWE-352
Origin Validation Error
|
CVE-2020-23582
|
2024-11-21 14:13 |
2022-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209149
|
9.8 |
CRITICAL
Network
|
mkcms_project
|
mkcms
|
MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.
|
CWE-89
SQL Injection
|
CVE-2020-22820
|
2024-11-21 14:13 |
2022-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209150
|
- |
|
-
|
-
|
Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive information via crafted payload to Category name component.
|
-
|
CVE-2020-22540
|
2024-11-21 14:13 |
2024-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|