|
211721
|
9.8 |
CRITICAL
Network
|
hp
|
intelligent_management_center
|
A accessmgrservlet classname deserialization of untrusted data remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P0…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-24648
|
2024-11-21 14:15 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211722
|
9.8 |
CRITICAL
Network
|
hp
|
intelligent_management_center
|
A remote accessmgrservlet classname input validation code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
|
CWE-20
Improper Input Validation
|
CVE-2020-24647
|
2024-11-21 14:15 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211723
|
9.8 |
CRITICAL
Network
|
hp
|
intelligent_management_center
|
A tftpserver stack-based buffer overflow remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
|
CWE-787
Out-of-bounds Write
|
CVE-2020-24646
|
2024-11-21 14:15 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211724
|
8.8 |
HIGH
Network
|
hp
|
intelligent_management_center
|
A remote operatoronlinelist_content privilege escalation vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
|
NVD-CWE-noinfo
|
CVE-2020-24630
|
2024-11-21 14:15 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211725
|
9.8 |
CRITICAL
Network
|
hp
|
intelligent_management_center
|
A remote urlaccesscontroller authentication bypass vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
|
CWE-287
Improper Authentication
|
CVE-2020-24629
|
2024-11-21 14:15 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211726
|
5.9 |
MEDIUM
Network
|
exposure_notifications_project
|
exposure_notifications
|
An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-10-05, as used in COVID-19 applications on Android and iOS. The encrypted metadata block with a TX …
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2020-24722
|
2024-11-21 14:15 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211727
|
8.8 |
HIGH
Network
|
hpe
|
kvm_ip_console_switch_g2_firmware
|
A remote code injection vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.
|
CWE-94
Code Injection
|
CVE-2020-24628
|
2024-11-21 14:15 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211728
|
5.4 |
MEDIUM
Network
|
hpe
|
kvm_ip_console_switch_g2_firmware
|
A remote stored xss vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24627
|
2024-11-21 14:15 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211729
|
6.5 |
MEDIUM
Network
|
mbconnectline
|
mymbconnect24 mbconnect24
|
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the lancompenent component, allowing logged-in attackers to discover arbitrar…
|
CWE-89
SQL Injection
|
CVE-2020-24568
|
2024-11-21 14:15 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211730
|
9.8 |
CRITICAL
Network
|
powerdns
|
authoritative
|
An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker might be able to cause a double-free, leading to a cras…
|
CWE-415
Double Free
|
CVE-2020-24698
|
2024-11-21 14:15 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|