|
197111
|
6.9 |
MEDIUM
Physics
|
mcafee
|
endpoint_security
|
Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows physical local users to bypass the Windows lock screen via tr…
|
CWE-287
Improper Authentication
|
CVE-2020-7323
|
2024-11-21 14:37 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197112
|
4.7 |
MEDIUM
Local
|
mcafee
|
endpoint_security
|
Information Disclosure Vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to gain access to sensitive information via incorrectly log…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-7322
|
2024-11-21 14:37 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197113
|
7.3 |
HIGH
Local
|
mcafee
|
endpoint_security
|
Protection Mechanism Failure vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local administrator to temporarily reduce the detection capabilit…
|
NVD-CWE-noinfo
|
CVE-2020-7320
|
2024-11-21 14:37 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197114
|
8.8 |
HIGH
Local
|
mcafee
|
endpoint_security
|
Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to access files which the user otherwise would not have ac…
|
CWE-59
Link Following
|
CVE-2020-7319
|
2024-11-21 14:37 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197115
|
4.1 |
MEDIUM
Local
|
mcafee
|
true_key
|
Cleartext Storage of Sensitive Information in Memory vulnerability in Microsoft Windows client in McAfee True Key (TK) prior to 6.2.109.2 allows a local user logged in with administrative privileges …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-7299
|
2024-11-21 14:37 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197116
|
9.8 |
CRITICAL
Network
|
bestzip_project
|
bestzip
|
The package bestzip before 2.1.7 are vulnerable to Command Injection via the options param.
|
CWE-78
OS Command
|
CVE-2020-7730
|
2024-11-21 14:37 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197117
|
6.5 |
MEDIUM
Local
|
rapid7
|
nexpose
|
Rapid7 Nexpose installer version prior to 6.6.40 contains an Unquoted Search Path which may allow an attacker on the local machine to insert an arbitrary file into the executable path. This issue aff…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2020-7382
|
2024-11-21 14:37 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197118
|
7.8 |
HIGH
Local
|
rapid7
|
nexpose
|
In Rapid7 Nexpose installer versions prior to 6.6.40, the Nexpose installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This …
|
CWE-94
Code Injection
|
CVE-2020-7381
|
2024-11-21 14:37 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197119
|
7.1 |
HIGH
Network
|
gruntjs debian canonical
|
grunt debian_linux ubuntu_linux
|
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside gr…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2020-7729
|
2024-11-21 14:37 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197120
|
7.8 |
HIGH
Local
|
raonwiz
|
raon_kupload
|
RAONWIZ v2018.0.2.50 and earlier versions contains a vulnerability that could allow remote files to be downloaded by lack of validation. Vulnerabilities in downloading with Kupload agent allow files …
|
CWE-20
Improper Input Validation
|
CVE-2020-7830
|
2024-11-21 14:37 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|