|
196831
|
7.4 |
HIGH
Local
|
checkpoint
|
zonealarm_anti-ransomware
|
ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked cont…
|
CWE-59
Link Following
|
CVE-2020-6012
|
2024-11-21 14:34 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196832
|
7.8 |
HIGH
Local
|
skygroup
|
skysea_client_view
|
Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unauthorized privileges and modify/obtain sensitive information or perform unintende…
|
CWE-269
Improper Privilege Management
|
CVE-2020-5617
|
2024-11-21 14:34 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196833
|
9.8 |
CRITICAL
Network
|
calendar02_project calendar01_project link01_project calendarform01_project gallery01_project telop01_project pkobo-vote01_project pkobo-news01_project
|
calendar02 calendar01 link01 calendarform01 gallery01 telop01 pkobo-vote01 pkobo-news01
|
[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News0…
|
CWE-287
Improper Authentication
|
CVE-2020-5616
|
2024-11-21 14:34 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196834
|
8.8 |
HIGH
Network
|
calendar02_project calendar01_project
|
calendar02 calendar01
|
Cross-site request forgery (CSRF) vulnerability in [Calendar01] free edition ver1.0.0 and [Calendar02] free edition ver1.0.0 allows remote attackers to hijack the authentication of administrators via…
|
CWE-352
Origin Validation Error
|
CVE-2020-5615
|
2024-11-21 14:34 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196835
|
8.8 |
HIGH
Network
|
teltonika-networks
|
trb245_firmware
|
Improper Access Control in Teltonika firmware TRB2_R_00.02.04.01 allows a low privileged user to perform unauthorized write operations.
|
CWE-269
Improper Privilege Management
|
CVE-2020-5773
|
2024-11-21 14:34 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196836
|
7.5 |
HIGH
Network
|
teltonika-networks
|
trb245_firmware
|
Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious package file.
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-5772
|
2024-11-21 14:34 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196837
|
7.5 |
HIGH
Network
|
teltonika-networks
|
trb245_firmware
|
Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious backup archive.
|
CWE-20
Improper Input Validation
|
CVE-2020-5771
|
2024-11-21 14:34 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196838
|
8.8 |
HIGH
Network
|
teltonika-networks
|
trb245_firmware
|
Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
|
CWE-352
Origin Validation Error
|
CVE-2020-5770
|
2024-11-21 14:34 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196839
|
5.7 |
MEDIUM
Network
|
vmware
|
tanzu_application_service_for_virtual_machines operations_manager
|
VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains an App Autoscaler that logs the UAA admin passwor…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-5414
|
2024-11-21 14:34 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196840
|
9.8 |
CRITICAL
Network
|
vmware oracle
|
spring_integration flexcube_private_banking retail_merchandising_system banking_virtual_account_management banking_credit_facilities_process_management banking_corporate_lending_proces…
|
Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered classes are resolved on d…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-5413
|
2024-11-21 14:34 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|