|
210641
|
9.8 |
CRITICAL
Network
|
globalradar
|
bsa_radar
|
Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeover of user accounts if successfully exploited. Th…
|
CWE-862
Missing Authorization
|
CVE-2020-14944
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210642
|
5.4 |
MEDIUM
Network
|
globalradar
|
bsa_radar
|
The Firstname and Lastname parameters in Global RADAR BSA Radar 1.6.7234.24750 and earlier are vulnerable to stored cross-site scripting (XSS) via Update User Profile.
|
CWE-79
Cross-site Scripting
|
CVE-2020-14943
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210643
|
7.1 |
HIGH
Local
|
iobit
|
advanced_systemcare
|
IOBit Advanced SystemCare Free 13.5.0.263 allows local users to gain privileges for file deletion by manipulating the Clean & Optimize feature with an NTFS junction and an Object Manager symbolic lin…
|
CWE-59
Link Following
|
CVE-2020-14990
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210644
|
9.8 |
CRITICAL
Network
|
chocolate-doom opensuse
|
crispy_doom chocolate_doom leap backports
|
The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading to a buffer overflow. A malicious user can overwrite the server's stack.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-14983
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210645
|
5.9 |
MEDIUM
Network
|
vipre
|
password_vault
|
The ThreatTrack VIPRE Password Vault app through 1.100.1090 for iOS has Missing SSL Certificate Validation.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-14981
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210646
|
5.9 |
MEDIUM
Network
|
sophos
|
sophos_secure_email
|
The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-14980
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210647
|
6.1 |
MEDIUM
Network
|
webtareas_project
|
webtareas
|
The loginForm within the general/login.php webpage in webTareas 2.0p8 suffers from a Reflected Cross Site Scripting (XSS) vulnerability via the query string.
|
CWE-79
Cross-site Scripting
|
CVE-2020-14973
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210648
|
9.8 |
CRITICAL
Network
|
pisay_online_e-learning_system_project
|
pisay_online_e-learning_system
|
Multiple SQL injection vulnerabilities in Sourcecodester Pisay Online E-Learning System 1.0 allow remote unauthenticated attackers to bypass authentication and achieve Remote Code Execution (RCE) via…
|
CWE-89
SQL Injection
|
CVE-2020-14972
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210649
|
7.5 |
HIGH
Network
|
misp
|
misp
|
app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable a…
|
CWE-862
Missing Authorization
|
CVE-2020-14969
|
2024-11-21 14:04 |
2020-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210650
|
9.8 |
CRITICAL
Network
|
jsrsasign_project netapp
|
jsrsasign max_data
|
An issue was discovered in the jsrsasign package before 8.0.17 for Node.js. Its RSASSA-PSS (RSA-PSS) implementation does not detect signature manipulation/modification by prepending '\0' bytes to a s…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-14968
|
2024-11-21 14:04 |
2020-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|