Search Results (79936 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-8015 2 Exim, Opensuse 2 Exim, Opensuse 2024-11-21 8.4 High
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: openSUSE Factory exim versions prior to 4.93.0.4-3.1.
CVE-2020-8014 1 Opensuse 2 Leap, Tumbleweed Kopano-spamd 2024-11-21 7.7 High
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE Leap 15.1, openSUSE Tumbleweed allowed local attackers with the privileges of the kopano user to escalate to root. This issue affects: openSUSE Leap 15.1 kopano-spamd versions prior to 10.0.5-lp151.4.1. openSUSE Tumbleweed kopano-spamd versions prior to 10.0.5-1.1.
CVE-2020-8011 1 Broadcom 1 Unified Infrastructure Management 2024-11-21 7.5 High
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a null pointer dereference vulnerability in the robot (controller) component. A remote attacker can crash the Controller service.
CVE-2020-8009 1 Motu 21 112d, 1248, 16a and 18 more 2024-11-21 7.5 High
AVB MOTU devices through 2020-01-22 allow /.. Directory Traversal, as demonstrated by reading the /etc/passwd file.
CVE-2020-8004 1 St 2 Stm32f1, Stm32f1 Firmware 2024-11-21 7.5 High
STMicroelectronics STM32F1 devices have Incorrect Access Control.
CVE-2020-7998 1 Super File Explorer Project 1 Super File Explorer 2024-11-21 8.8 High
An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the root path. By default, there is no password set for the FTP or Web UI service.
CVE-2020-7991 1 Adive 1 Framework 2024-11-21 8.8 High
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
CVE-2020-7988 1 Phpipam 1 Phpipam 2024-11-21 8.8 High
An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old password, and the lack of security tokens.
CVE-2020-7984 1 Solarwinds 1 N-central 2024-11-21 7.5 High
SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information. The attacker can use a customer ID to self register and read any aspects of the agent/appliance configuration.
CVE-2020-7983 1 Commscope 2 Ruckus Zoneflex R500, Ruckus Zoneflex R500 Firmware 2024-11-21 8.1 High
A CSRF issue in login.asp on Ruckus R500 3.4.2.0.384 devices allows remote attackers to access the panel or conduct SSRF attacks.
CVE-2020-7982 1 Openwrt 2 Lede, Openwrt 2024-11-21 8.1 High
An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the opkg package manager before 2020-01-25 prevents correct parsing of embedded checksums in the signed repository index, allowing a man-in-the-middle attacker to inject arbitrary package payloads (which are installed without verification).
CVE-2020-7978 1 Gitlab 1 Gitlab 2024-11-21 7.5 High
GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.
CVE-2020-7972 1 Gitlab 1 Gitlab 2024-11-21 7.5 High
GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).
CVE-2020-7969 1 Gitlab 1 Gitlab 2024-11-21 7.5 High
GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.
CVE-2020-7968 1 Gitlab 1 Gitlab 2024-11-21 7.5 High
GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.
CVE-2020-7966 1 Gitlab 1 Gitlab 2024-11-21 7.5 High
GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.
CVE-2020-7965 1 Webargs Project 1 Webargs 2024-11-21 8.8 High
flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input. If the request body is valid JSON, it will accept it even if the content type is application/x-www-form-urlencoded. This allows for JSON POST requests to be made across domains, leading to CSRF.
CVE-2020-7954 1 Opservices 1 Opmon 2024-11-21 7.8 High
An issue was discovered in OpServices OpMon 9.3.2. Starting from the apache user account, it is possible to perform privilege escalation through the lack of correct configuration in the server's sudoers file, which by default allows the execution of programs (e.g. nmap) without the need for a password with sudo.
CVE-2020-7953 1 Opservices 1 Opmon 2024-11-21 7.5 High
An issue was discovered in OpServices OpMon 9.3.2. Without authentication, it is possible to read server files (e.g., /etc/passwd) due to the use of the nmap -iL (aka input file) option.
CVE-2020-7952 1 Valvesoftware 1 Dota 2 2024-11-21 7.8 High
rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is affected by memory corruption.