| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-10712 | Hig | 0.46 | 7.0 | 0.01 | Apr 22, 2020 | A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator allowing an attacker able to gain access to those logs, to read and write to the storage backing the internal image registry. The… | ||
| CVE-2018-21126 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2020 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17. | ||
| CVE-2018-21125 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2020 | NETGEAR WAC510 devices before 5.0.0.17 are affected by authentication bypass. | ||
| CVE-2018-21124 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2020 | NETGEAR WAC510 devices before 5.0.0.17 are affected by privilege escalation. | ||
| CVE-2018-21123 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2020 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WC7500 before 6.5.3.9, WC7520 before 6.5.3.9, WC7600v1 before 6.5.3.9, and WC7600v2 before 6.5.3.9. | ||
| CVE-2018-21121 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2020 | Certain NETGEAR devices are affected by authentication bypass. This affects GS810EMX before 1.0.0.5, XS512EM before 1.0.0.6, and XS724EM before 1.0.0.6. | ||
| CVE-2018-21120 | Hig | 0.52 | 8.0 | 0.00 | Apr 22, 2020 | Certain NETGEAR devices are affected by CSRF. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WNAP320 before 3.7.11.4, WNAP210v2 before 3.7.11.4, WNDAP350 before 3.7.11.4, WNDAP360 before 3.7.11.4, WNDAP660 before 3.7.11.4, WNDAP620 before 2.1.7,… | ||
| CVE-2018-21118 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2020 | NETGEAR XR500 devices before 2.3.2.32 are affected by authentication bypass. | ||
| CVE-2017-18768 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2020 | Certain NETGEAR devices are affected by CSRF. This affects EX6100 before 1.0.2.16_1.1.130, EX6100v2 before 1.0.1.70, EX6150v2 before 1.0.1.54, EX6200v2 before 1.0.1.50, EX6400 before 1.0.1.60, EX7300 before 1.0.1.60, and WN3000RPv3 before 1.0.2.44. | ||
| CVE-2017-18764 | Hig | 0.57 | 8.8 | 0.02 | Apr 22, 2020 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.0.55, D7000 before 1.0.1.50, D7800 before 1.0.1.28, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.18,… | ||
| CVE-2017-18762 | Hig | 0.57 | 8.8 | 0.02 | Apr 22, 2020 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D3600 before 1.0.0.68, D6000 before 1.0.0.68, D6100 before 1.0.0.57, R6100 before 1.0.1.16, R6900P before 1.2.0.22, R7000 before 1.0.9.10, R7000P before 1.2.0.22, R7100LG… | ||
| CVE-2020-8477 | Hig | 0.57 | 8.8 | 0.02 | Apr 22, 2020 | The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead to execution of arbitrary code. | ||
| CVE-2020-8474 | Hig | 0.51 | 7.8 | 0.00 | Apr 22, 2020 | Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings related to control system functionality, allowing an authenticated attacker to cause system functions to stop or malfunction. | ||
| CVE-2018-21117 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2020 | NETGEAR XR500 devices before 2.3.2.32 are affected by remote code execution by unauthenticated attackers via the traceroute handler. | ||
| CVE-2018-21116 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2020 | NETGEAR XR500 devices before 2.3.2.32 are affected by remote code execution by unauthenticated attackers. | ||
| CVE-2018-21115 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2020 | NETGEAR XR500 devices before 2.3.2.32 are affected by remote code execution by unauthenticated attackers. | ||
| CVE-2018-21113 | Hig | 0.57 | 8.8 | 0.02 | Apr 22, 2020 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.0.58, D7800 before 1.0.1.42, R6100 before 1.0.1.28, R7500 before 1.0.0.130, R7500v2 before 1.0.3.36, R7800 before 1.0.2.52, R8900 before 1.0.4.12, R9000 before… | ||
| CVE-2017-18787 | Hig | 0.51 | 7.8 | 0.01 | Apr 22, 2020 | Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050, before 1.0.1.12, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and… | ||
| CVE-2017-18786 | Hig | 0.51 | 7.8 | 0.01 | Apr 22, 2020 | Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050 before 1.0.1.12, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and… | ||
| CVE-2017-18782 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2020 | Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JR6150 before 1.0.1.12, JNR1010v2 before 1.1.0.44, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6020 before 1.0.0.26, R6050 before 1.0.1.12, R6080 before 1.0.0.26,… | ||
| CVE-2017-18781 | Hig | 0.57 | 8.8 | 0.00 | Apr 22, 2020 | Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JNR1010v2 before 1.1.0.44, JWNR2010v5 before 1.1.0.44, JR6150 before 1.0.1.12, PR2000 before 1.0.0.20, R6020 before 1.0.0.26, R6050 before 1.0.1.12, R6080 before 1.0.0.26,… | ||
| CVE-2017-18779 | Hig | 0.51 | 7.8 | 0.00 | Apr 22, 2020 | Certain NETGEAR devices are affected by a buffer overflow. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6020 before 1.0.0.26, R6050 before 1.0.1.12, R6080… | ||
| CVE-2017-18777 | Hig | 0.51 | 7.8 | 0.00 | Apr 22, 2020 | Certain NETGEAR devices are affected by administrative password disclosure. This affects D6220 before V1.0.0.28, D6400 before V1.0.0.60, D8500 before V1.0.3.29, DGN2200v4 before 1.0.0.82, DGN2200Bv4 before 1.0.0.82, R6300v2 before 1.0.4.8, R6400 before 1.0.1.20, R6700 before… | ||
| CVE-2017-18776 | Hig | 0.55 | 8.4 | 0.00 | Apr 22, 2020 | Certain NETGEAR devices are affected by authentication bypass. This affects D6100 before V1.0.0.55, D7000 before V1.0.1.50, D7800 before V1.0.1.24, JNR1010v2 before 1.1.0.40, JWNR2010v5 before 1.1.0.40, R6100 before 1.0.1.12, R6220 before 1.1.0.50, R7500 before 1.0.0.108,… | ||
| CVE-2017-18775 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2020 | Certain NETGEAR devices are affected by CSRF. This affects R6100 before 1.0.1.12, R7500 before 1.0.0.108, WNDR3700v4 before 1.0.2.86, WNDR4300v1 before 1.0.2.88, WNDR4300v2 before 1.0.0.48, WNDR4500v3 before 1.0.0.48, and WNR2000v5 before 1.0.0.42. | ||
| CVE-2017-18772 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2020 | Certain NETGEAR devices are affected by authentication bypass. This affects EX3700 before 1.0.0.64, EX3800 before 1.0.0.64, EX6120 before 1.0.0.32, EX6130 before 1.0.0.16, R6300v2 before 1.0.4.12, R6700 before 1.0.1.26, R6900 before 1.0.1.22, R7000 before 1.0.9.6, R7300DST… | ||
| CVE-2020-11795 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2020 | In JetBrains Space through 2020-04-22, the session timeout period was configured improperly. | ||
| CVE-2020-11693 | Hig | 0.49 | 7.5 | 0.02 | Apr 22, 2020 | JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue. | ||
| CVE-2020-11691 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2020 | In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible. | ||
| CVE-2020-11688 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2020 | In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session. | ||
| CVE-2020-11687 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2020 | In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages. | ||
| CVE-2020-11685 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2020 | In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS. | ||
| CVE-2020-11539 | Hig | 0.53 | 8.1 | 0.01 | Apr 22, 2020 | An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE security level) The data being transmitted over the air is not encrypted. Adding to this, the data being sent to the smart band… | ||
| CVE-2020-12059 | Hig | 0.49 | 7.5 | 0.03 | Apr 22, 2020 | An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception. | ||
| CVE-2020-12051 | Hig | 0.49 | 7.5 | 0.01 | Apr 21, 2020 | The CentralAuth extension through REL1_34 for MediaWiki allows remote attackers to obtain sensitive hidden account information via an api.php?action=query&meta=globaluserinfo&guiuser= request. In other words, the information can be retrieved via the action API even though access… | ||
| CVE-2019-4327 | Hig | 0.49 | 7.5 | 0.01 | Apr 21, 2020 | "HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files." | ||
| CVE-2019-17525 | Hig | 0.61 | 8.8 | 0.06 | Apr 21, 2020 | The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks. | ||
| CVE-2017-18799 | Hig | 0.49 | 7.5 | 0.01 | Apr 21, 2020 | Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R6200v2 before 1.0.3.14, R6250 before 1.0.4.8, R6300v2 before 1.0.4.8, R6700 before 1.1.1.20, R7000 before 1.0.7.10, R7000P/R6900P before 1.0.0.56, R7100LG before 1.0.0.30, R7900… | ||
| CVE-2017-18794 | Hig | 0.55 | 8.4 | 0.01 | Apr 21, 2020 | Certain NETGEAR devices are affected by command injection. This affects R6300v2 before 1.0.4.8_10.0.77, R6400 before 1.0.1.24, R6700 before 1.0.1.26, R7000 before 1.0.9.10, R7100LG before 1.0.0.32, R7900 before 1.0.1.18, R8000 before 1.0.3.54, R8500 before 1.0.2.100, and D6100… | ||
| CVE-2017-18792 | Hig | 0.55 | 8.4 | 0.01 | Apr 21, 2020 | NETGEAR D6100 devices before 1.0.0.50_0.0.50 are affected by command injection. | ||
| CVE-2017-18791 | Hig | 0.57 | 8.8 | 0.00 | Apr 21, 2020 | Certain NETGEAR devices are affected by CSRF. This affects R6050/JR6150 before 1.0.1.7, PR2000 before 1.0.0.17, R6220 before 1.1.0.50, WNDR3700v5 before 1.1.0.48, JNR1010v2 before 1.1.0.40, JWNR2010v5 before 1.1.0.40, WNR1000v4 before 1.1.0.40, WNR2020 before 1.1.0.40, WNR2050… | ||
| CVE-2020-8895 | Hig | 0.51 | 7.8 | 0.00 | Apr 21, 2020 | Untrusted Search Path vulnerability in the windows installer of Google Earth Pro versions prior to 7.3.3 allows an attacker to insert malicious local files to execute unauthenticated remote code on the targeted system. | ||
| CVE-2020-1757 | Hig | 0.53 | 8.1 | 0.02 | Apr 21, 2020 | A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which… | ||
| CVE-2020-1699 | Hig | 0.49 | 7.5 | 0.02 | Apr 21, 2020 | A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use this flaw to cause information disclosure on the host machine… | ||
| CVE-2020-10787 | Hig | 0.57 | 8.8 | 0.03 | Apr 21, 2020 | An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the admin account via v-change-user-password (aka the user password change script). | ||
| CVE-2020-10786 | Hig | 0.58 | 8.8 | 0.05 | Apr 21, 2020 | A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron jobs. | ||
| CVE-2019-8961 | Hig | 0.49 | 7.5 | 0.02 | Apr 21, 2020 | A Denial of Service vulnerability related to stack exhaustion has been identified in FlexNet Publisher lmadmin.exe 11.16.2. Because the message reading function calls itself recursively given a certain condition in the received message, an unauthenticated remote attacker can… | ||
| CVE-2019-8960 | Hig | 0.49 | 7.5 | 0.01 | Apr 21, 2020 | A Denial of Service vulnerability related to command handling has been identified in FlexNet Publisher lmadmin.exe version 11.16.2. The message reading function used in lmadmin.exe can, given a certain message, call itself again and then wait for a further message. With a… | ||
| CVE-2020-1967 | Hig | 0.53 | 7.5 | 0.53 | Apr 21, 2020 | Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or… | ||
| CVE-2020-11828 | Hig | 0.49 | 7.5 | 0.01 | Apr 21, 2020 | In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), RGB is defined on the stack but uninitialized, so when the screenShot function to RGB value assignment, will not initialize the value is… |
- risk 0.46cvss 7.0epss 0.01
A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator allowing an attacker able to gain access to those logs, to read and write to the storage backing the internal image registry. The…
- risk 0.57cvss 8.8epss 0.01
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17.
- risk 0.57cvss 8.8epss 0.01
NETGEAR WAC510 devices before 5.0.0.17 are affected by authentication bypass.
- risk 0.57cvss 8.8epss 0.01
NETGEAR WAC510 devices before 5.0.0.17 are affected by privilege escalation.
- risk 0.57cvss 8.8epss 0.01
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WC7500 before 6.5.3.9, WC7520 before 6.5.3.9, WC7600v1 before 6.5.3.9, and WC7600v2 before 6.5.3.9.
- risk 0.57cvss 8.8epss 0.01
Certain NETGEAR devices are affected by authentication bypass. This affects GS810EMX before 1.0.0.5, XS512EM before 1.0.0.6, and XS724EM before 1.0.0.6.
- risk 0.52cvss 8.0epss 0.00
Certain NETGEAR devices are affected by CSRF. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WNAP320 before 3.7.11.4, WNAP210v2 before 3.7.11.4, WNDAP350 before 3.7.11.4, WNDAP360 before 3.7.11.4, WNDAP660 before 3.7.11.4, WNDAP620 before 2.1.7,…
- risk 0.57cvss 8.8epss 0.01
NETGEAR XR500 devices before 2.3.2.32 are affected by authentication bypass.
- risk 0.57cvss 8.8epss 0.01
Certain NETGEAR devices are affected by CSRF. This affects EX6100 before 1.0.2.16_1.1.130, EX6100v2 before 1.0.1.70, EX6150v2 before 1.0.1.54, EX6200v2 before 1.0.1.50, EX6400 before 1.0.1.60, EX7300 before 1.0.1.60, and WN3000RPv3 before 1.0.2.44.
- risk 0.57cvss 8.8epss 0.02
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.0.55, D7000 before 1.0.1.50, D7800 before 1.0.1.28, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.18,…
- risk 0.57cvss 8.8epss 0.02
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D3600 before 1.0.0.68, D6000 before 1.0.0.68, D6100 before 1.0.0.57, R6100 before 1.0.1.16, R6900P before 1.2.0.22, R7000 before 1.0.9.10, R7000P before 1.2.0.22, R7100LG…
- risk 0.57cvss 8.8epss 0.02
The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead to execution of arbitrary code.
- risk 0.51cvss 7.8epss 0.00
Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings related to control system functionality, allowing an authenticated attacker to cause system functions to stop or malfunction.
- risk 0.57cvss 8.8epss 0.01
NETGEAR XR500 devices before 2.3.2.32 are affected by remote code execution by unauthenticated attackers via the traceroute handler.
- risk 0.57cvss 8.8epss 0.01
NETGEAR XR500 devices before 2.3.2.32 are affected by remote code execution by unauthenticated attackers.
- risk 0.57cvss 8.8epss 0.01
NETGEAR XR500 devices before 2.3.2.32 are affected by remote code execution by unauthenticated attackers.
- risk 0.57cvss 8.8epss 0.02
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.0.58, D7800 before 1.0.1.42, R6100 before 1.0.1.28, R7500 before 1.0.0.130, R7500v2 before 1.0.3.36, R7800 before 1.0.2.52, R8900 before 1.0.4.12, R9000 before…
- risk 0.51cvss 7.8epss 0.01
Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050, before 1.0.1.12, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and…
- risk 0.51cvss 7.8epss 0.01
Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050 before 1.0.1.12, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and…
- risk 0.57cvss 8.8epss 0.01
Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JR6150 before 1.0.1.12, JNR1010v2 before 1.1.0.44, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6020 before 1.0.0.26, R6050 before 1.0.1.12, R6080 before 1.0.0.26,…
- risk 0.57cvss 8.8epss 0.00
Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JNR1010v2 before 1.1.0.44, JWNR2010v5 before 1.1.0.44, JR6150 before 1.0.1.12, PR2000 before 1.0.0.20, R6020 before 1.0.0.26, R6050 before 1.0.1.12, R6080 before 1.0.0.26,…
- risk 0.51cvss 7.8epss 0.00
Certain NETGEAR devices are affected by a buffer overflow. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6020 before 1.0.0.26, R6050 before 1.0.1.12, R6080…
- risk 0.51cvss 7.8epss 0.00
Certain NETGEAR devices are affected by administrative password disclosure. This affects D6220 before V1.0.0.28, D6400 before V1.0.0.60, D8500 before V1.0.3.29, DGN2200v4 before 1.0.0.82, DGN2200Bv4 before 1.0.0.82, R6300v2 before 1.0.4.8, R6400 before 1.0.1.20, R6700 before…
- risk 0.55cvss 8.4epss 0.00
Certain NETGEAR devices are affected by authentication bypass. This affects D6100 before V1.0.0.55, D7000 before V1.0.1.50, D7800 before V1.0.1.24, JNR1010v2 before 1.1.0.40, JWNR2010v5 before 1.1.0.40, R6100 before 1.0.1.12, R6220 before 1.1.0.50, R7500 before 1.0.0.108,…
- risk 0.57cvss 8.8epss 0.01
Certain NETGEAR devices are affected by CSRF. This affects R6100 before 1.0.1.12, R7500 before 1.0.0.108, WNDR3700v4 before 1.0.2.86, WNDR4300v1 before 1.0.2.88, WNDR4300v2 before 1.0.0.48, WNDR4500v3 before 1.0.0.48, and WNR2000v5 before 1.0.0.42.
- risk 0.57cvss 8.8epss 0.01
Certain NETGEAR devices are affected by authentication bypass. This affects EX3700 before 1.0.0.64, EX3800 before 1.0.0.64, EX6120 before 1.0.0.32, EX6130 before 1.0.0.16, R6300v2 before 1.0.4.12, R6700 before 1.0.1.26, R6900 before 1.0.1.22, R7000 before 1.0.9.6, R7300DST…
- risk 0.49cvss 7.5epss 0.01
In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.
- risk 0.49cvss 7.5epss 0.02
JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages.
- risk 0.49cvss 7.5epss 0.01
In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.
- risk 0.53cvss 8.1epss 0.01
An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE security level) The data being transmitted over the air is not encrypted. Adding to this, the data being sent to the smart band…
- risk 0.49cvss 7.5epss 0.03
An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception.
- risk 0.49cvss 7.5epss 0.01
The CentralAuth extension through REL1_34 for MediaWiki allows remote attackers to obtain sensitive hidden account information via an api.php?action=query&meta=globaluserinfo&guiuser= request. In other words, the information can be retrieved via the action API even though access…
- risk 0.49cvss 7.5epss 0.01
"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."
- risk 0.61cvss 8.8epss 0.06
The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.
- risk 0.49cvss 7.5epss 0.01
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R6200v2 before 1.0.3.14, R6250 before 1.0.4.8, R6300v2 before 1.0.4.8, R6700 before 1.1.1.20, R7000 before 1.0.7.10, R7000P/R6900P before 1.0.0.56, R7100LG before 1.0.0.30, R7900…
- risk 0.55cvss 8.4epss 0.01
Certain NETGEAR devices are affected by command injection. This affects R6300v2 before 1.0.4.8_10.0.77, R6400 before 1.0.1.24, R6700 before 1.0.1.26, R7000 before 1.0.9.10, R7100LG before 1.0.0.32, R7900 before 1.0.1.18, R8000 before 1.0.3.54, R8500 before 1.0.2.100, and D6100…
- risk 0.55cvss 8.4epss 0.01
NETGEAR D6100 devices before 1.0.0.50_0.0.50 are affected by command injection.
- risk 0.57cvss 8.8epss 0.00
Certain NETGEAR devices are affected by CSRF. This affects R6050/JR6150 before 1.0.1.7, PR2000 before 1.0.0.17, R6220 before 1.1.0.50, WNDR3700v5 before 1.1.0.48, JNR1010v2 before 1.1.0.40, JWNR2010v5 before 1.1.0.40, WNR1000v4 before 1.1.0.40, WNR2020 before 1.1.0.40, WNR2050…
- risk 0.51cvss 7.8epss 0.00
Untrusted Search Path vulnerability in the windows installer of Google Earth Pro versions prior to 7.3.3 allows an attacker to insert malicious local files to execute unauthenticated remote code on the targeted system.
- risk 0.53cvss 8.1epss 0.02
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which…
- risk 0.49cvss 7.5epss 0.02
A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use this flaw to cause information disclosure on the host machine…
- risk 0.57cvss 8.8epss 0.03
An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the admin account via v-change-user-password (aka the user password change script).
- risk 0.58cvss 8.8epss 0.05
A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron jobs.
- risk 0.49cvss 7.5epss 0.02
A Denial of Service vulnerability related to stack exhaustion has been identified in FlexNet Publisher lmadmin.exe 11.16.2. Because the message reading function calls itself recursively given a certain condition in the received message, an unauthenticated remote attacker can…
- risk 0.49cvss 7.5epss 0.01
A Denial of Service vulnerability related to command handling has been identified in FlexNet Publisher lmadmin.exe version 11.16.2. The message reading function used in lmadmin.exe can, given a certain message, call itself again and then wait for a further message. With a…
- risk 0.53cvss 7.5epss 0.53
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or…
- risk 0.49cvss 7.5epss 0.01
In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), RGB is defined on the stack but uninitialized, so when the screenShot function to RGB value assignment, will not initialize the value is…