|
210291
|
4.3 |
MEDIUM
Network
|
librehealth
|
librehealth_ehr
|
LibreHealth EMR v2.0.0 is affected by SQL injection allowing low-privilege authenticated users to enumerate the database.
|
CWE-89
SQL Injection
|
CVE-2020-11437
|
2024-11-21 13:57 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210292
|
9.0 |
CRITICAL
Network
|
librehealth
|
librehealth_ehr
|
LibreHealth EMR v2.0.0 is vulnerable to XSS that results in the ability to force arbitrary actions on behalf of other users including administrators.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11436
|
2024-11-21 13:57 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210293
|
9.1 |
CRITICAL
Network
|
inetsoftware
|
pdfc helpdesk clear_reports
|
The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remote unauthenticated attacker to read arbitrary system files and directories on th…
|
CWE-22
Path Traversal
|
CVE-2020-11431
|
2024-11-21 13:57 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210294
|
7.5 |
HIGH
Network
|
openvpn
|
openvpn_access_server
|
An issue was discovered in OpenVPN Access Server before 2.7.0 and 2.8.x before 2.8.3. With the full featured RPC2 interface enabled, it is possible to achieve a temporary DoS state of the management …
|
CWE-776
XML Entity Expansion
|
CVE-2020-11462
|
2024-11-21 13:57 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210295
|
8.1 |
HIGH
Network
|
zoom
|
it_installer
|
The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoom before installing an updated version of the client. Standard users are able t…
|
CWE-59 CWE-732
Link Following Incorrect Permission Assignment for Critical Resource
|
CVE-2020-11443
|
2024-11-21 13:57 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210296
|
7.8 |
HIGH
Local
|
eset
|
internet_security nod32_antivirus smart_security endpoint_security endpoint_antivirus mail_security file_security antivirus_and_antispyware
|
ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these…
|
CWE-59
Link Following
|
CVE-2020-11446
|
2024-11-21 13:57 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210297
|
4.9 |
MEDIUM
Network
|
sonatype
|
nexus_repository_manager
|
An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cle…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-11415
|
2024-11-21 13:57 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210298
|
6.5 |
MEDIUM
Network
|
abb generex
|
cs141_firmware
|
UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by manipulating variables that reference files and by do…
|
CWE-22
Path Traversal
|
CVE-2020-11420
|
2024-11-21 13:57 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210299
|
5.4 |
MEDIUM
Network
|
jetbrains
|
space
|
JetBrains Space through 2020-04-22 allows stored XSS in Chats.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11416
|
2024-11-21 13:57 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210300
|
8.8 |
HIGH
Network
|
sonatype
|
nexus
|
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-11444
|
2024-11-21 13:57 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|