|
196301
|
9.8 |
CRITICAL
Network
|
salesagility
|
suitecrm
|
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4).
|
CWE-89
SQL Injection
|
CVE-2020-8786
|
2024-11-21 14:39 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196302
|
9.8 |
CRITICAL
Network
|
salesagility
|
suitecrm
|
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4).
|
CWE-89
SQL Injection
|
CVE-2020-8785
|
2024-11-21 14:39 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196303
|
9.8 |
CRITICAL
Network
|
salesagility
|
suitecrm
|
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4).
|
CWE-89
SQL Injection
|
CVE-2020-8784
|
2024-11-21 14:39 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196304
|
9.8 |
CRITICAL
Network
|
salesagility
|
suitecrm
|
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4).
|
CWE-89
SQL Injection
|
CVE-2020-8783
|
2024-11-21 14:39 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196305
|
7.5 |
HIGH
Network
|
netapp
|
storagegrid
|
StorageGRID (formerly StorageGRID Webscale) versions 10.0.0 through 11.3 prior to 11.2.0.8 and 11.3.0.4 are susceptible to a vulnerability which allows an unauthenticated remote attacker to cause a D…
|
NVD-CWE-noinfo
|
CVE-2020-8571
|
2024-11-21 14:39 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196306
|
5.5 |
MEDIUM
Local
|
huawei
|
honor_v30_firmware
|
Huawei smartphone Honor V30 with versions earlier than OxfordS-AN00A 10.0.1.167(C00E166R4P1) have an improper authentication vulnerability. Authentication to target component is improper when device …
|
CWE-287
Improper Authentication
|
CVE-2020-9064
|
2024-11-21 14:39 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196307
|
9.1 |
CRITICAL
Network
|
johnsoncontrols
|
metasys_system_configuration_tool metasys_lonworks_control_server metasys_open_application_server metasys_open_data_server metasys_extended_application_and_data_server metasys_applicat…
|
XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files. This affects Johnson Controls' Metasys Ap…
|
CWE-611
XXE
|
CVE-2020-9044
|
2024-11-21 14:39 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196308
|
7.4 |
HIGH
Network
|
avast
|
avg_antitrack antitrack
|
Avast AntiTrack before 1.5.1.172 and AVG Antitrack before 2.0.0.178 proxies traffic to HTTPS sites but does not validate certificates, and thus a man-in-the-middle can host a malicious website using …
|
CWE-295
Improper Certificate Validation
|
CVE-2020-8987
|
2024-11-21 14:39 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196309
|
7.8 |
HIGH
Local
|
wftpserver
|
wing_ftp_server
|
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local users to arbitrarily create FTP users with full p…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-8635
|
2024-11-21 14:39 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196310
|
7.8 |
HIGH
Local
|
wftpserver
|
wing_ftp_server
|
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting in files being saved with world-readable and worl…
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-8634
|
2024-11-21 14:39 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|