|
209141
|
7.5 |
HIGH
Network
|
tinyexr_project
|
tinyexr
|
tinyexr 0.9.5 was discovered to contain an array index error in the tinyexr::DecodeEXRImage component, which can lead to a denial of service (DOS).
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-18430
|
2024-11-21 14:08 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209142
|
7.5 |
HIGH
Network
|
tinyexr_project
|
tinyexr
|
tinyexr commit 0.9.5 was discovered to contain an array index error in the tinyexr::SaveEXR component, which can lead to a denial of service (DOS).
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-18428
|
2024-11-21 14:08 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209143
|
9.8 |
CRITICAL
Network
|
autohotkey
|
autohotkey
|
A process injection vulnerability in setup.exe of AutoHotkey 1.1.32.00 allows attackers to escalate privileges.
|
NVD-CWE-noinfo
|
CVE-2020-18174
|
2024-11-21 14:08 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209144
|
7.8 |
HIGH
Local
|
1password
|
1password
|
A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-18173
|
2024-11-21 14:08 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209145
|
9.8 |
CRITICAL
Network
|
trezor
|
bridge
|
A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate privileges.
|
CWE-94
Code Injection
|
CVE-2020-18172
|
2024-11-21 14:08 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209146
|
8.8 |
HIGH
Local
|
techsmith
|
snagit
|
TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to escalate privileges. NOTE: This implies that Snagit's use o…
|
CWE-269
Improper Privilege Management
|
CVE-2020-18171
|
2024-11-21 14:08 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209147
|
9.8 |
CRITICAL
Network
|
abloy
|
key_manager
|
An issue in the SeChangeNotifyPrivilege component of Abloy Key Manager Version 7.14301.0.0 allows attackers to escalate privileges via a change in permissions.
|
NVD-CWE-Other
|
CVE-2020-18170
|
2024-11-21 14:08 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209148
|
7.8 |
HIGH
Local
|
techsmith
|
snagit
|
A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate privileges. NOTE: Exploit of the Snagit installer would require the end user to…
|
CWE-269
Improper Privilege Management
|
CVE-2020-18169
|
2024-11-21 14:08 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209149
|
9.8 |
CRITICAL
Network
|
twothink_project
|
twothink
|
A remote code execution (RCE) vulnerability in /library/think/App.php of Twothink v2.0 allows attackers to execute arbitrary PHP code.
|
NVD-CWE-noinfo
|
CVE-2020-17952
|
2024-11-21 14:08 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209150
|
9.8 |
CRITICAL
Network
|
intelliants
|
subrion
|
SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection.
|
CWE-89
SQL Injection
|
CVE-2020-18155
|
2024-11-21 14:08 |
2021-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|