|
197171
|
6.4 |
MEDIUM
Network
|
mcafee
|
data_loss_prevention
|
Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to upload malicious files to the DLP case management …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-7302
|
2024-11-21 14:37 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197172
|
4.6 |
MEDIUM
Network
|
mcafee
|
data_loss_prevention
|
Cross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to trigger alerts via the file upload tab in the DLP case manageme…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7301
|
2024-11-21 14:37 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197173
|
6.3 |
MEDIUM
Network
|
mcafee
|
data_loss_prevention
|
Improper Authorization vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attackers to change the configuration when logged in with view only…
|
CWE-863
Incorrect Authorization
|
CVE-2020-7300
|
2024-11-21 14:37 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197174
|
7.8 |
HIGH
Local
|
documalis
|
free_pdf_scanner free_pdf_editor
|
Documalis Free PDF Editor version 5.7.2.26 and Documalis Free PDF Scanner version 5.7.2.122 do not appropriately validate the contents of JPEG images contained within a PDF. Attackers can exploit thi…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-7374
|
2024-11-21 14:37 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197175
|
8.8 |
HIGH
Network
|
handysoft
|
hslogin2.dll
|
hslogin2.dll ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method. This is due to a lack of…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-7810
|
2024-11-21 14:37 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197176
|
7.8 |
HIGH
Local
|
raonwiz
|
k_upload
|
MyBrowserPlus downloads the files needed to run the program through the setup file (Setup.inf). At this time, there is a vulnerability in downloading arbitrary files due to insufficient integrity ver…
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-7817
|
2024-11-21 14:37 |
2020-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197177
|
7.0 |
HIGH
Local
|
freebsd
|
freebsd
|
In FreeBSD 12.1-STABLE before r363918, 12.1-RELEASE before p8, 11.4-STABLE before r363919, 11.4-RELEASE before p2, and 11.3-RELEASE before p12, the sendmsg system call in the compat32 subsystem on 64…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2020-7460
|
2024-11-21 14:37 |
2020-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197178
|
6.8 |
MEDIUM
Physics
|
freebsd
|
freebsd
|
In FreeBSD 12.1-STABLE before r362166, 12.1-RELEASE before p8, 11.4-STABLE before r362167, 11.4-RELEASE before p2, and 11.3-RELEASE before p12, missing length validation code common to mulitple USB n…
|
CWE-20
Improper Input Validation
|
CVE-2020-7459
|
2024-11-21 14:37 |
2020-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197179
|
8.8 |
HIGH
Network
|
easycorp
|
zentao_pro
|
The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, attackers may construct …
|
CWE-78
OS Command
|
CVE-2020-7361
|
2024-11-21 14:37 |
2020-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197180
|
9.9 |
CRITICAL
Network
|
cayintech
|
cms-se_firmware cms-se-lxc_firmware cms-60_firmware cms-40_firmware cms-20_firmware cms
|
Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user …
|
CWE-78
OS Command
|
CVE-2020-7357
|
2024-11-21 14:37 |
2020-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|