Latest CVE Feed
-
9.8
CRITICALCVE-2020-8782
Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution.... Read more
Affected Products : aleos airlink_es440 airlink_es450 airlink_gx440 airlink_gx450 airlink_ls300 airlink_lx40 airlink_lx60 airlink_mp70 airlink_mp70e +4 more products- Published: Oct. 06, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-8781
Lack of input sanitization in UpdateRebootMgr service of ALEOS 4.11 and later allow an escalation to root from a low-privilege process.... Read more
Affected Products : aleos airlink_es440 airlink_es450 airlink_gx440 airlink_gx450 airlink_ls300 airlink_lx40 airlink_lx60 airlink_mp70 airlink_mp70e +4 more products- Published: Oct. 06, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8778
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write access to a project.... Read more
Affected Products : alfresco- Published: Mar. 02, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8777
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT element in an SVG document.... Read more
Affected Products : alfresco- Published: Mar. 02, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8776
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a file.... Read more
Affected Products : alfresco- Published: Mar. 02, 2020
- Modified: Nov. 21, 2024
-
8.9
HIGHCVE-2020-8775
Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.... Read more
- Published: Apr. 29, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2020-8774
Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.... Read more
- Published: Apr. 29, 2020
- Modified: Nov. 21, 2024
-
8.9
HIGHCVE-2020-8773
The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability.... Read more
- Published: Apr. 29, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8772
The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.... Read more
Affected Products : infinitewp_client- Published: Feb. 06, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8771
The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be logged in as the first account on the list of administrator accounts.... Read more
Affected Products : wp_time_capsule- Published: Feb. 06, 2020
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2020-8768
An issue was discovered on Phoenix Contact Emalytics Controller ILC 2050 BI before 1.2.3 and BI-L before 1.2.3 devices. There is an insecure mechanism for read and write access to the configuration of the device. The mechanism can be discovered by examini... Read more
- Published: Feb. 17, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-8767
Uncaught exception in the Intel(R) 50GbE IP Core for Intel(R) Quartus Prime before version 20.2 may allow an authenticated user to potentially enable denial of service via local access.... Read more
Affected Products : quartus_prime- Published: Nov. 12, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2020-8766
Improper conditions check in the Intel(R) SGX DCAP software before version 1.6 may allow an unauthenticated user to potentially enable denial of service via adjacent access.... Read more
Affected Products : software_guard_extensions_data_center_attestation_primitives- Published: Nov. 12, 2020
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2020-8765
Incorrect default permissions in the installer for the Intel(R) RealSense(TM) DCM may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
- Published: Feb. 17, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2020-8764
Improper access control in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products : hci_compute_node_bios xeon_bronze_3104 xeon_bronze_3106 bios xeon_silver_4214 aff_bios fas_bios hci_storage_node_bios solidfire_bios core_i5-7640x +327 more products- Published: Nov. 12, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-8763
Improper permissions in the installer for the Intel(R) RealSense(TM) D400 Series UWP driver for Windows* 10 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : windows_10 realsense_d415_firmware realsense_d435_firmware realsense_d435i_firmware- Published: Aug. 13, 2020
- Modified: Nov. 21, 2024
-
4.6
MEDIUMCVE-2020-8761
Inadequate encryption strength in subsystem for Intel(R) CSME versions before 13.0.40 and 13.30.10 may allow an unauthenticated user to potentially enable information disclosure via physical access.... Read more
Affected Products : converged_security_and_manageability_engine- Published: Nov. 12, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-8760
Integer overflow in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45 may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
- Published: Nov. 12, 2020
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2020-8759
Improper access control in the installer for Intel(R) SSD DCT versions before 3.0.23 may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products : ssd_data_center_tool- Published: Aug. 13, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8758
Improper buffer restrictions in network subsystem in provisioned Intel(R) AMT and Intel(R) ISM versions before 11.8.79, 11.12.79, 11.22.79, 12.0.68 and 14.0.39 may allow an unauthenticated user to potentially enable escalation of privilege via network acc... Read more
- Published: Sep. 10, 2020
- Modified: Nov. 21, 2024