|
209771
|
7.2 |
HIGH
Network
|
projectworlds
|
official_car_rental_system
|
An issue was discovered in Project Worlds Official Car Rental System 1. It allows the admin user to run commands on the server with their account because the upload section on the file-manager page c…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-11544
|
2024-11-21 13:58 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209772
|
7.8 |
HIGH
Local
|
malwarebytes
|
adwcleaner
|
An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner 8.0.3 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded.
|
CWE-426
Untrusted Search Path
|
CVE-2020-11507
|
2024-11-21 13:58 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209773
|
6.0 |
MEDIUM
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
An issue was discovered in the Linux kernel through 5.6.2. mpol_parse_str in mm/mempolicy.c has a stack-based out-of-bounds write because an empty nodelist is mishandled during mount option parsing, …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-11565
|
2024-11-21 13:58 |
2020-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209774
|
9.8 |
CRITICAL
Network
|
gpac
|
gpac
|
An issue was discovered in libgpac.a in GPAC 0.8.0, as demonstrated by MP4Box. audio_sample_entry_Read in isomedia/box_code_base.c does not properly decide when to make gf_isom_box_del calls. This le…
|
CWE-416
Use After Free
|
CVE-2020-11558
|
2024-11-21 13:58 |
2020-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209775
|
9.8 |
CRITICAL
Network
|
search_meter_project
|
search_meter
|
The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-11548
|
2024-11-21 13:58 |
2020-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209776
|
5.3 |
MEDIUM
Network
|
paessler
|
prtg_network_monitor
|
PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal stat…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-11547
|
2024-11-21 13:58 |
2020-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209777
|
9.8 |
CRITICAL
Network
|
3xlogic
|
infinias_eidc32_firmware infinias_eidc32_web
|
3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the <KEY>MYKEY</KEY> substring.
|
CWE-287 CWE-319
Improper Authentication Cleartext Transmission of Sensitive Information
|
CVE-2020-11542
|
2024-11-21 13:58 |
2020-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209778
|
5.5 |
MEDIUM
Local
|
ivanti
|
workspace_control
|
Ivanti Workspace Control before 10.4.30.0, when SCCM integration is enabled, allows local users to obtain sensitive information (keying material).
|
NVD-CWE-noinfo
|
CVE-2020-11533
|
2024-11-21 13:58 |
2020-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209779
|
6.1 |
MEDIUM
Network
|
getgrav
|
grav
|
Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.
|
CWE-601
Open Redirect
|
CVE-2020-11529
|
2024-11-21 13:58 |
2020-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209780
|
7.5 |
HIGH
Network
|
bit2spr_project
|
bit2spr
|
bit2spr 1992-06-07 has a stack-based buffer overflow (129-byte write) in conv_bitmap in bit2spr.c via a long line in a bitmap file.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-11528
|
2024-11-21 13:58 |
2020-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|