|
209381
|
7.1 |
HIGH
Local
|
kaspersky
|
vpn_secure_connection
|
The installer of Kaspersky VPN Secure Connection prior to 5.0 was vulnerable to arbitrary file deletion that could allow an attacker to delete any file in the system.
|
NVD-CWE-noinfo
|
CVE-2020-25043
|
2024-11-21 14:16 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209382
|
4.3 |
MEDIUM
Network
|
derhansen
|
event_management_and_registration
|
The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows Information Disclosure (participant data, and event data via email) because of Br…
|
NVD-CWE-noinfo
|
CVE-2020-25026
|
2024-11-21 14:16 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209383
|
4.3 |
MEDIUM
Network
|
localization_manager_project
|
localization_manager
|
The l10nmgr (aka Localization Manager) extension before 7.4.0, 8.x before 8.7.0, and 9.x before 9.2.0 for TYPO3 allows Information Disclosure (translatable fields).
|
CWE-863
Incorrect Authorization
|
CVE-2020-25025
|
2024-11-21 14:16 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209384
|
7.8 |
HIGH
Local
|
superantispyware
|
professional_x
|
SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via…
|
CWE-59
Link Following
|
CVE-2020-24955
|
2024-11-21 14:16 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209385
|
5.5 |
MEDIUM
Local
|
google
|
android
|
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The USB driver leaks address information via kernel logging. The Samsung IDs are SVE-2020-17602, SVE-2020-…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-25046
|
2024-11-21 14:16 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209386
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_adselfservice_plus manageengine_exchange_reporter_plus manageengine_ad360 manageengine_datasecurity_plus manageengine_recovermanager_plus manageengine_eventlog_analyzer
|
An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before bui…
|
CWE-287
Improper Authentication
|
CVE-2020-24786
|
2024-11-21 14:16 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209387
|
6.1 |
MEDIUM
Network
|
blubrry
|
subscribe_sidebar
|
The Blubrry subscribe-sidebar (aka Subscribe Sidebar) plugin 1.3.1 for WordPress allows subscribe_sidebar.php&status= reflected XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25033
|
2024-11-21 14:16 |
2020-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209388
|
7.5 |
HIGH
Network
|
flask-cors_project debian opensuse
|
flask-cors debian_linux leap backports_sle
|
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathna…
|
CWE-22
Path Traversal
|
CVE-2020-25032
|
2024-11-21 14:16 |
2020-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209389
|
7.8 |
HIGH
Local
|
canonical
|
checkinstall
|
checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 executable file.
|
CWE-59
Link Following
|
CVE-2020-25031
|
2024-11-21 14:16 |
2020-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209390
|
6.1 |
MEDIUM
Network
|
osticket
|
osticket
|
osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24917
|
2024-11-21 14:16 |
2020-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|