|
209051
|
8.8 |
HIGH
Adjacent
|
senstar
|
symphony
|
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Senstar Symphony 7.3.2.2. Authentication is not required to exploit this vulnerability. The…
|
-
|
CVE-2020-17405
|
2024-11-21 14:08 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209052
|
6.1 |
MEDIUM
Network
|
forgerock
|
identity_manager
|
Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS. The vulnerability affects versions 6.5.0.4, 6.0.0.6.
|
CWE-79
Cross-site Scripting
|
CVE-2020-17465
|
2024-11-21 14:08 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209053
|
5.4 |
MEDIUM
Network
|
halo
|
halo
|
Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then execute in the victim user's browser.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19007
|
2024-11-21 14:08 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209054
|
5.7 |
MEDIUM
Network
|
zrlog
|
zrlog
|
zrlog v2.1.0 has a vulnerability with the permission check. If admin account is logged in, other unauthorized users can download the database backup file directly.
|
CWE-863
Incorrect Authorization
|
CVE-2020-19005
|
2024-11-21 14:08 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209055
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_studio_photo
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the …
|
-
|
CVE-2020-17404
|
2024-11-21 14:08 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209056
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_studio_photo
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the …
|
-
|
CVE-2020-17403
|
2024-11-21 14:08 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209057
|
6.5 |
MEDIUM
Local
|
parallels
|
parallels_desktop
|
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4 (47270). An attacker must first obtain the ability to execute low-pri…
|
-
|
CVE-2020-17402
|
2024-11-21 14:08 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209058
|
6.0 |
MEDIUM
Local
|
parallels
|
parallels_desktop
|
This vulnerability allows local attackers to disclose sensitive informations on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute high-privilege…
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-17401
|
2024-11-21 14:08 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209059
|
8.8 |
HIGH
Local
|
parallels
|
parallels_desktop
|
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute low-privileged code on the…
|
-
|
CVE-2020-17400
|
2024-11-21 14:08 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209060
|
8.8 |
HIGH
Local
|
parallels
|
parallels_desktop
|
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute low-privileged code on the…
|
-
|
CVE-2020-17399
|
2024-11-21 14:08 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|