|
209941
|
8.1 |
HIGH
Network
|
zoom
|
it_installer
|
The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoom before installing an updated version of the client. Standard users are able t…
|
CWE-59 CWE-732
Link Following Incorrect Permission Assignment for Critical Resource
|
CVE-2020-11443
|
2024-11-21 13:57 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209942
|
7.8 |
HIGH
Local
|
eset
|
internet_security nod32_antivirus smart_security endpoint_security endpoint_antivirus mail_security file_security antivirus_and_antispyware
|
ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these…
|
CWE-59
Link Following
|
CVE-2020-11446
|
2024-11-21 13:57 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209943
|
4.9 |
MEDIUM
Network
|
sonatype
|
nexus_repository_manager
|
An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cle…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-11415
|
2024-11-21 13:57 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209944
|
6.5 |
MEDIUM
Network
|
abb generex
|
cs141_firmware
|
UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by manipulating variables that reference files and by do…
|
CWE-22
Path Traversal
|
CVE-2020-11420
|
2024-11-21 13:57 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209945
|
5.4 |
MEDIUM
Network
|
jetbrains
|
space
|
JetBrains Space through 2020-04-22 allows stored XSS in Chats.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11416
|
2024-11-21 13:57 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209946
|
8.8 |
HIGH
Network
|
sonatype
|
nexus
|
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-11444
|
2024-11-21 13:57 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209947
|
5.3 |
MEDIUM
Network
|
microstrategy
|
microstrategy_web
|
Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStrategyWS/. The functionality requires no authentication and,…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-11453
|
2024-11-21 13:57 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209948
|
4.3 |
MEDIUM
Network
|
microstrategy
|
microstrategy_web
|
Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases. By providing an external URL under attacker control, it's possi…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-11452
|
2024-11-21 13:57 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209949
|
5.4 |
MEDIUM
Network
|
microstrategy
|
microstrategy_web
|
Microstrategy Web 10.4 is vulnerable to Stored XSS in the HTML Container and Insert Text features in the window, allowing for the creation of a new dashboard. In order to exploit this vulnerability, …
|
CWE-79
Cross-site Scripting
|
CVE-2020-11454
|
2024-11-21 13:57 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209950
|
7.2 |
HIGH
Network
|
microstrategy
|
microstrategy_web
|
The Upload Visualization plugin in the Microstrategy Web 10.4 admin panel allows an administrator to upload a ZIP archive containing files with arbitrary extensions and data. (This is also exploitabl…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-11451
|
2024-11-21 13:57 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|