|
197421
|
7.8 |
HIGH
Local
|
druva
|
insync
|
inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privileged user due to improper integrity checks and directory permi…
|
CWE-276 CWE-354
Incorrect Default Permissions Improper Validation of Integrity Check Value
|
CVE-2020-5798
|
2024-11-21 14:34 |
2020-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197422
|
7.5 |
HIGH
Network
|
mitsubishielectric
|
gt2107-wtbd_firmware gt2107-wtsd_firmware gt2104-rtbd_firmware gt2104-pmbd_firmware gt2103-pmbd_firmware gs2110-wtbd_firmware gs2107-wtbd_firmware le7-40gu-l_firmware gs2110-w…
|
Out-of-bounds read vulnerability in GT21 model of GOT2000 series (GT2107-WTBD V01.39.000 and earlier, GT2107-WTSD V01.39.000 and earlier, GT2104-RTBD V01.39.000 and earlier, GT2104-PMBD V01.39.000 an…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-5675
|
2024-11-21 14:34 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197423
|
7.8 |
HIGH
Local
|
checkpoint
|
endpoint_security
|
Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-6021
|
2024-11-21 14:34 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197424
|
9.8 |
CRITICAL
Network
|
valvesoftware
|
game_networking_sockets
|
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment() when configured to support plain-text messages, leading …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6017
|
2024-11-21 14:34 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197425
|
7.5 |
HIGH
Network
|
ec-cube
|
ec-cube
|
Improper input validation vulnerability in EC-CUBE versions from 3.0.5 to 3.0.18 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vector.
|
CWE-20
Improper Input Validation
|
CVE-2020-5680
|
2024-11-21 14:34 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197426
|
6.1 |
MEDIUM
Network
|
ec-cube
|
ec-cube
|
Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking attacks. If a user accesses a specially crafted page while logged into the administ…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-5679
|
2024-11-21 14:34 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197427
|
6.1 |
MEDIUM
Network
|
weseek
|
growi
|
Stored cross-site scripting vulnerability in GROWI v3.8.1 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5678
|
2024-11-21 14:34 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197428
|
6.1 |
MEDIUM
Network
|
weseek
|
growi
|
Reflected cross-site scripting vulnerability in GROWI v4.0.0 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5677
|
2024-11-21 14:34 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197429
|
7.5 |
HIGH
Network
|
weseek
|
growi
|
GROWI v4.1.3 and earlier allow remote attackers to obtain information which is not allowed to access via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2020-5676
|
2024-11-21 14:34 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197430
|
6.1 |
MEDIUM
Network
|
desknets
|
neo
|
Cross-site scripting vulnerability in desknet's NEO (desknet's NEO Small License V5.5 R1.5 and earlier, and desknet's NEO Enterprise License V5.5 R1.5 and earlier) allows remote attackers to inject a…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5638
|
2024-11-21 14:34 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|