|
202861
|
9.8 |
CRITICAL
Network
|
oklok_project
|
oklok
|
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could…
|
CWE-307 CWE-521
mproper Restriction of Excessive Authentication Attempts Weak Password Requirements
|
CVE-2020-8790
|
2024-11-21 14:39 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202862
|
8.9 |
HIGH
Network
|
pega
|
platform
|
Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8775
|
2024-11-21 14:39 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202863
|
8.8 |
HIGH
Network
|
pega
|
pega_platform
|
Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8774
|
2024-11-21 14:39 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202864
|
8.9 |
HIGH
Network
|
pega
|
platform
|
The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8773
|
2024-11-21 14:39 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202865
|
9.8 |
CRITICAL
Network
|
huawei
|
ar3200_firmware
|
Huawei AR3200 products with versions of V200R007C00SPC900, V200R007C00SPCa00, V200R007C00SPCb00, V200R007C00SPCc00, V200R009C00SPC500 have an improper authentication vulnerability. Attackers need to …
|
CWE-287
Improper Authentication
|
CVE-2020-9068
|
2024-11-21 14:39 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202866
|
6.7 |
MEDIUM
Local
|
huawei
|
osd_firmware
|
Huawei OSD product with versions earlier than OSD_uwp_9.0.32.0 have a local privilege escalation vulnerability. An authenticated, local attacker can constructs a specific file path to exploit this vu…
|
NVD-CWE-noinfo
|
CVE-2020-9072
|
2024-11-21 14:39 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202867
|
5.5 |
MEDIUM
Local
|
juplink
|
rx4-1500_firmware
|
httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the unauthenticated setup3.htm endpoint from the local network.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-8798
|
2024-11-21 14:39 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202868
|
6.7 |
MEDIUM
Local
|
juplink
|
rx4-1500_firmware
|
Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line Injection), if the undocumented telnetd service is enabled an…
|
CWE-78
OS Command
|
CVE-2020-8797
|
2024-11-21 14:39 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202869
|
4.7 |
MEDIUM
Local
|
canonical apport_project
|
ubuntu_linux apport
|
Time-of-check Time-of-use Race Condition vulnerability on crash report ownership change in Apport allows for a possible privilege escalation opportunity. If fs.protected_symlinks is disabled, this ca…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2020-8833
|
2024-11-21 14:39 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202870
|
5.5 |
MEDIUM
Local
|
canonical apport_project
|
ubuntu_linux apport
|
Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport directory. If the apport/ directory does not exist (this is not uncommon as /var/lock is a tmpfs),…
|
CWE-59
Link Following
|
CVE-2020-8831
|
2024-11-21 14:39 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|