Unknown · CVSS Not scored
An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the user to conduct remote code execution via admin/borrower/index.php?view=add because .php files can be uploaded to admin/borrower/photos (under the web root).
Published Nov 17, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&status=0&id=,?g=Team&m=Task&a=my&status=1&id=,?g=Team&m=Task&a=my&status=10&id=
Published Nov 17, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability in "Documents component" found in AudimexEE version 14.1.0 allows an attacker to execute arbitrary SQL commands via the object_path parameter.
Published Nov 5, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parameter via search.php.
Published Nov 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group Corporation allows a local unprivileged attacker, such as a malicious App, to read & write to the /data/vendor/tcl, /data/vendor/upgrade, and /var/TerminalManager directories within the TV file system. An attacker, such as a malicious APK or local unprivileged user could perform fake system upgrades by writing to the /data/vendor/upgrage folder.
Published Nov 10, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
AudimexEE before 14.1.1 is vulnerable to Reflected XSS (Cross-Site-Scripting). If the recommended security configuration parameter "unique_error_numbers" is not set, remote attackers can inject arbitrary web script or HTML via 'action, cargo, panel' parameters that can lead to data leakage.
Published Nov 5, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in ProlinOS through 2.4.161.8859R. An attacker with local code execution privileges as a normal user (MAINAPP) can escalate to root privileges by exploiting the setuid installation of the xtables-multi binary and leveraging the ip6tables --modprobe switch.
Published Nov 1, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
JamoDat TSMManager Collector version up to 6.5.0.21 is vulnerable to an Authorization Bypass because the Collector component is not properly validating an authenticated session with the Viewer. If the Viewer has been modified (binary patched) and the Bypass Login functionality is being used, an attacker can request every Collector's functionality as if they were a properly logged-in user: administrating connected instances, reviewing logs, editing configurations, accessing the instances' consoles, accessing hardware configurations, etc.Exploiting this vulnerability won't grant an attacker access nor control on remote ISP servers as no credentials is sent with the request.
Published Nov 19, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An attacker with physical access to a PAX Point Of Sale device with ProlinOS through 2.4.161.8859R can boot it in management mode, enable the XCB service, and then list, read, create, and overwrite files with MAINAPP permissions.
Published Nov 1, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An unsigned-library issue was discovered in ProlinOS through 2.4.161.8859R. This OS requires installed applications and all system binaries to be signed either by the manufacturer or by the Point Of Sale application developer and distributor. The signature is a 2048-byte RSA signature verified in the kernel prior to ELF execution. Shared libraries, however, do not need to be signed, and they are not verified. An attacker may execute a custom binary by compiling it as a shared object and loading it via LD_PRELOAD.
Published Nov 1, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The SIP ALG implementation on NETGEAR Nighthawk R7000 1.0.9.64_10.2.64 devices allows remote attackers to communicate with arbitrary TCP and UDP services on a victim's intranet machine, if the victim visits an attacker-controlled web site with a modern browser, aka NAT Slipstreaming. This occurs because the ALG takes action based on an IP packet with an initial REGISTER substring in the TCP data, and the correct intranet IP address in the subsequent Via header, without properly considering that connection progress and fragmentation affect the meaning of the packet data.
Published Nov 1, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read the Connect CA private key configuration. Fixed in 1.6.10, 1.7.10, and 1.8.6.
Published Nov 23, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ServiceStack before 5.9.2 mishandles JWT signature verification unless an application has a custom ValidateToken function that establishes a valid minimum length for a signature.
Published Nov 1, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.
Published Nov 1, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard).
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
CapaSystems CapaInstaller before 6.0.101 does not properly assign, modify, or check privileges for an actor who attempts to edit registry values, allowing an attacker to escalate privileges.
Published Nov 9, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
IceWarp 11.4.5.0 allows XSS via the language parameter.
Published Nov 9, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent).
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field).
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Git LFS 2.12.0 allows Remote Code Execution.
Published Nov 5, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
httpd on TP-Link TL-WPA4220 devices (hardware versions 2 through 4) allows remote authenticated users to trigger a buffer overflow (causing a denial of service) by sending a POST request to the /admin/syslog endpoint. Fixed version: TL-WPA4220(EU)_V4_201023
Published Nov 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Security Onion v2 prior to 2.3.10 has an incorrect sudo configuration, which allows the administrative user to obtain root access without using the sudo password by editing and executing /home/<user>/SecurityOnion/setup/so-setup.
Published Nov 23, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability was found in Linux kernel, where a use-after-frees in nouveau's postclose() handler could happen if removing device (that is not common to remove video card physically without power-off, but same happens if "unbind" the driver).
Published Nov 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 has updated a specific critical library that may vulnerable to attack.
Published Nov 9, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Slurm before 19.05.8 and 20.x before 20.02.6 exposes Sensitive Information to an Unauthorized Actor because xauth for X11 magic cookies is affected by a race condition in a read operation on the /proc filesystem.
Published Nov 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin.
Published Nov 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains undocumented default admin credentials for the web management interface. A remote attacker could exploit this vulnerability to login and execute commands on the device, as well as upgrade the firmware image to a malicious version.
Published Nov 4, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a non-protected location with high privileges (symlink attack) which can lead to obtaining administrative privileges during the installation of the product.
Published Nov 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 stores administrative passwords using a hash that is considered outdated.
Published Nov 9, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any itemType (e.g., Ticket, Users, etc.).
Published Nov 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains multiple CSRF vulnerabilities within its web management portal. Attackers can, for example, use this to update the TR-069 configuration server settings (responsible for managing devices remotely). This makes it possible to remotely reboot the device or upload malicious firmware.
Published Nov 4, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
RVToolsPasswordEncryption.exe in RVTools 4.0.6 allows users to encrypt passwords to be used in the configuration files. This encryption used a static IV and key, and thus using the Decrypt() method from VISKD.cs from the RVTools.exe executable allows for decrypting the encrypted passwords. The accounts used in the configuration files have access to vSphere instances.
Published Nov 5, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_tickets, glpi_users, etc.).
Published Nov 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a specific Windows system directory which can lead to obtaining administrative privileges during the installation of the product.
Published Nov 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a local directory which can lead to obtaining administrative privileges during the installation of the product.
Published Nov 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 allows XSS via URLBlocking Settings, SNMP Settings, and System Log Settings.
Published Nov 4, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains a buffer overflow within its web management portal. When a POST request is sent to /boaform/admin/formDOMAINBLK with a large blkDomain value, the Boa server crashes.
Published Nov 4, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF.
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use of an undocumented user in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to view the video stream.
Published Nov 17, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ati_2d_blt in hw/display/ati_2d.c in QEMU 4.2.1 can encounter an outside-limits situation in a calculation. A guest can crash the QEMU process.
Published Nov 6, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
JetBrains IdeaVim before version 0.58 might have caused an information leak in limited circumstances.
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In JetBrains TeamCity before 2020.1.5, secure dependency parameters could be not masked in depending builds when there are no internal artifacts.
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cleartext Transmission of Sensitive Information vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 exists which could leak sensitive information transmitted between the mobile app and the camera device.
Published Nov 17, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A predictable device ID in BASETech GE-131 BT-1837836 firmware 20180921 allows unauthenticated remote attackers to connect to the device.
Published Nov 17, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues.
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings via a brute-attack on the settings password.
Published Nov 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers %x; %p; %c and %s in the screen_key, display_name, browser_name, and operation_system parameter during the authentication process. This may crash the server and force Solstice-Pod to reboot, which leads to a denial of service.
Published Nov 11, 2020 · Updated Aug 4, 2024