|
209231
|
6.5 |
MEDIUM
Network
|
mbconnectline
|
mymbconnect24 mbconnect24
|
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the lancompenent component, allowing logged-in attackers to discover arbitrar…
|
CWE-89
SQL Injection
|
CVE-2020-24568
|
2024-11-21 14:15 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209232
|
9.8 |
CRITICAL
Network
|
powerdns
|
authoritative
|
An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker might be able to cause a double-free, leading to a cras…
|
CWE-415
Double Free
|
CVE-2020-24698
|
2024-11-21 14:15 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209233
|
7.5 |
HIGH
Network
|
powerdns
|
authoritative
|
An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker can cause a denial of service by sending crafted querie…
|
NVD-CWE-noinfo
|
CVE-2020-24697
|
2024-11-21 14:15 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209234
|
8.1 |
HIGH
Network
|
powerdns
|
authoritative
|
An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker can trigger a race condition leading to a crash, or pos…
|
CWE-362
Race Condition
|
CVE-2020-24696
|
2024-11-21 14:15 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209235
|
7.8 |
HIGH
Local
|
unisys
|
stealth
|
Unisys Stealth(core) before 4.0.134 stores passwords in a recoverable format. Therefore, a search of Enterprise Manager can potentially reveal credentials.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-24620
|
2024-11-21 14:15 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209236
|
5.7 |
MEDIUM
Physics
|
apple google
|
exposure_notifications
|
An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-09-29, as used in COVID-19 applications on Android and iOS. It allows a user to be put in a positio…
|
NVD-CWE-noinfo
|
CVE-2020-24721
|
2024-11-21 14:15 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209237
|
6.5 |
MEDIUM
Network
|
mbconnectline
|
mymbconnect24 mbconnect24
|
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24proxy module, allowing attackers to steal session in…
|
CWE-352 CWE-918
Origin Validation Error Server-Side Request Forgery (SSRF)
|
CVE-2020-24570
|
2024-11-21 14:15 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209238
|
4.3 |
MEDIUM
Network
|
mbconnectline
|
mymbconnect24 mbconnect24
|
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the knximport component via an advanced attack vector, allowing logged in att…
|
CWE-89
SQL Injection
|
CVE-2020-24569
|
2024-11-21 14:15 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209239
|
5.5 |
MEDIUM
Local
|
trendmicro
|
apex_one
|
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installation…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-24565
|
2024-11-21 14:15 |
2020-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209240
|
5.5 |
MEDIUM
Local
|
trendmicro
|
apex_one
|
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installation…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-24564
|
2024-11-21 14:15 |
2020-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|