|
209041
|
9.8 |
CRITICAL
Network
|
mpxj oracle
|
mpxj primavera_unifier
|
MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.
|
CWE-611
XXE
|
CVE-2020-25020
|
2024-11-21 14:16 |
2020-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209042
|
7.5 |
HIGH
Network
|
jitsi
|
meet_electron
|
jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-25019
|
2024-11-21 14:16 |
2020-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209043
|
9.1 |
CRITICAL
Network
|
rgb-rust_project
|
rgb-rust
|
A safety violation was discovered in the rgb crate before 0.8.20 for Rust, leading to (for example) dereferencing of arbitrary pointers or disclosure of uninitialized memory. This occurs because stru…
|
CWE-119 CWE-843
Incorrect Access of Indexable Resource ('Range Error') Type Confusion
|
CVE-2020-25016
|
2024-11-21 14:16 |
2020-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209044
|
7.8 |
HIGH
Local
|
br-automation
|
automation_studio automation_net\/pvi
|
Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Auto…
|
-
|
CVE-2020-24682
|
2024-11-21 14:15 |
2024-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209045
|
8.8 |
HIGH
Local
|
br-automation
|
automation_studio
|
Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through…
|
-
|
CVE-2020-24681
|
2024-11-21 14:15 |
2024-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209046
|
5.5 |
MEDIUM
Local
|
ghost
|
sqlite3
|
Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service via a crafted script.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-24736
|
2024-11-21 14:15 |
2023-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209047
|
9.8 |
CRITICAL
Network
|
capexweb_project
|
capexweb
|
Shilpi CAPExWeb 1.1 allows SQL injection via a servlet/capexweb.cap_sendMail GET request.
|
CWE-89
SQL Injection
|
CVE-2020-24600
|
2024-11-21 14:15 |
2022-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209048
|
9.8 |
CRITICAL
Network
|
abb
|
base_software
|
A vulnerability in Base Software for SoftControl allows an attacker to insert and run arbitrary code in a computer running the affected product. This issue affects: .
|
CWE-20
Improper Input Validation
|
CVE-2020-24672
|
2024-11-21 14:15 |
2021-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209049
|
8.8 |
HIGH
Network
|
netskope
|
netskope
|
Netskope Client through 77 allows low-privileged users to elevate their privileges to NT AUTHORITY\SYSTEM.
|
CWE-269
Improper Privilege Management
|
CVE-2020-24576
|
2024-11-21 14:15 |
2021-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209050
|
8.8 |
HIGH
Network
|
tracefinanacial
|
crestbridge
|
Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03.
|
CWE-89
SQL Injection
|
CVE-2020-24671
|
2024-11-21 14:15 |
2021-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|