|
209121
|
5.7 |
MEDIUM
Physics
|
apple google
|
exposure_notifications
|
An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-09-29, as used in COVID-19 applications on Android and iOS. It allows a user to be put in a positio…
|
NVD-CWE-noinfo
|
CVE-2020-24721
|
2024-11-21 14:15 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209122
|
6.5 |
MEDIUM
Network
|
mbconnectline
|
mymbconnect24 mbconnect24
|
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24proxy module, allowing attackers to steal session in…
|
CWE-352 CWE-918
Origin Validation Error Server-Side Request Forgery (SSRF)
|
CVE-2020-24570
|
2024-11-21 14:15 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209123
|
4.3 |
MEDIUM
Network
|
mbconnectline
|
mymbconnect24 mbconnect24
|
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the knximport component via an advanced attack vector, allowing logged in att…
|
CWE-89
SQL Injection
|
CVE-2020-24569
|
2024-11-21 14:15 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209124
|
5.5 |
MEDIUM
Local
|
trendmicro
|
apex_one
|
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installation…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-24565
|
2024-11-21 14:15 |
2020-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209125
|
5.5 |
MEDIUM
Local
|
trendmicro
|
apex_one
|
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installation…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-24564
|
2024-11-21 14:15 |
2020-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209126
|
8.2 |
HIGH
Local
|
freebsd omniosce openindiana netapp
|
freebsd omnios openindiana clustered_data_ontap
|
bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demons…
|
CWE-862
Missing Authorization
|
CVE-2020-24718
|
2024-11-21 14:15 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209127
|
7.1 |
HIGH
Local
|
mitel
|
micontact_center_business
|
The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allo…
|
CWE-79 CWE-20
Cross-site Scripting Improper Input Validation
|
CVE-2020-24692
|
2024-11-21 14:15 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209128
|
8.8 |
HIGH
Network
|
openmrs
|
htmlformentry
|
A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS. By leveraging path traversal, a malicious Velocity Template Lan…
|
CWE-22
Path Traversal
|
CVE-2020-24621
|
2024-11-21 14:15 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209129
|
5.3 |
MEDIUM
Network
|
pexip
|
pexip_infinity
|
Pexip Infinity before 24.1 has Improper Input Validation, leading to temporary denial of service via SIP.
|
CWE-20
Improper Input Validation
|
CVE-2020-24615
|
2024-11-21 14:15 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209130
|
5.3 |
MEDIUM
Network
|
mitel
|
micloud_management_portal
|
Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to retrieve sensitive information due to insufficient access control.
|
NVD-CWE-noinfo
|
CVE-2020-24595
|
2024-11-21 14:15 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|