|
196961
|
9.8 |
CRITICAL
Network
|
fortinet
|
fortisiem_windows_agent
|
An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt executable service path.
|
CWE-428
Unquoted Search Path or Element
|
CVE-2020-9292
|
2024-11-21 14:40 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196962
|
7.8 |
HIGH
Local
|
fortinet
|
forticlient
|
An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain elevated privileges via exhausting the pool of temporary file names combined with a …
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-9291
|
2024-11-21 14:40 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196963
|
7.0 |
HIGH
Local
|
apache debian opensuse fedoraproject canonical oracle mcafee
|
tomcat debian_linux leap fedora ubuntu_linux transportation_management hospitality_guest_access managed_file_transfer retail_order_broker agile_plm database instantis…
|
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-9484
|
2024-11-21 14:40 |
2020-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196964
|
8.8 |
HIGH
Network
|
tibco oracle
|
jasperreports_library jasperreports_server retail_order_broker
|
The report generator component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server for AWS M…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9410
|
2024-11-21 14:40 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196965
|
9.8 |
CRITICAL
Network
|
tibco oracle
|
jasperreports_server retail_order_broker
|
The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vul…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-9409
|
2024-11-21 14:40 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196966
|
5.4 |
MEDIUM
Network
|
microfocus
|
enterprise_developer enterprise_server
|
Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Update 8. The vulnerability could allow an attacker to …
|
CWE-79
Cross-site Scripting
|
CVE-2020-9524
|
2024-11-21 14:40 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196967
|
9.8 |
CRITICAL
Network
|
dahuasecurity
|
sd6al_firmware sd5a_firmware sd1a_firmware ptz1a_firmware sd50_firmware sd52c_firmware ipc-hx5842h_firmware ipc-hx7842h_firmware ipc-hx2xxx_firmware ipc-hxxx5x4x_firmware
|
Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packe…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-9502
|
2024-11-21 14:40 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196968
|
5.5 |
MEDIUM
Local
|
dahuasecurity
|
web_p2p
|
Attackers can obtain Cloud Key information from the Dahua Web P2P control in specific ways. Cloud Key is used to authenticate the connection between the client tool and the platform. An attacker may …
|
NVD-CWE-noinfo
|
CVE-2020-9501
|
2024-11-21 14:40 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196969
|
7.5 |
HIGH
Network
|
oracle
|
iplanet_web_server
|
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-9315
|
2024-11-21 14:40 |
2020-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196970
|
4.8 |
MEDIUM
Network
|
oracle
|
iplanet_web_server
|
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists b…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9314
|
2024-11-21 14:40 |
2020-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|