|
210961
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10 windows_server_2016 windows_server_2019
|
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0888.
|
NVD-CWE-noinfo
|
CVE-2020-0784
|
2024-11-21 13:54 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210962
|
8.8 |
HIGH
Network
|
microsoft
|
publisher powerpoint word access visio excel outlook office project office_365_proplus
|
A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CV…
|
NVD-CWE-noinfo
|
CVE-2020-0760
|
2024-11-21 13:54 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210963
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_server_2016 windows_10 windows_server_2019
|
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020…
|
NVD-CWE-noinfo
|
CVE-2020-0699
|
2024-11-21 13:54 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210964
|
8.8 |
HIGH
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019
|
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.
|
NVD-CWE-noinfo
|
CVE-2020-0687
|
2024-11-21 13:54 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210965
|
7.2 |
HIGH
Network
|
sonatype
|
nexus
|
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
|
CWE-20
Improper Input Validation
|
CVE-2020-10204
|
2024-11-21 13:54 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210966
|
4.8 |
MEDIUM
Network
|
sonatype
|
nexus
|
Sonatype Nexus Repository before 3.21.2 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10203
|
2024-11-21 13:54 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210967
|
8.8 |
HIGH
Network
|
sonatype
|
nexus
|
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2020-10199
|
2024-11-21 13:54 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210968
|
6.5 |
MEDIUM
Network
|
zimbra
|
zm-mailbox
|
cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account. This differs from the intended behavior in which the domain of the…
|
CWE-862
Missing Authorization
|
CVE-2020-10194
|
2024-11-21 13:54 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210969
|
6.5 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 84.0.20 allows a webmail or demo account to delete arbitrary files (SEC-547).
|
NVD-CWE-noinfo
|
CVE-2020-10122
|
2024-11-21 13:54 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210970
|
9.8 |
CRITICAL
Network
|
cpanel
|
cpanel
|
cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546).
|
NVD-CWE-Other
|
CVE-2020-10121
|
2024-11-21 13:54 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|