|
210491
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_server_2016 windows_10 windows_server_2019
|
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020…
|
NVD-CWE-noinfo
|
CVE-2020-0699
|
2024-11-21 13:54 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210492
|
8.8 |
HIGH
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019
|
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.
|
NVD-CWE-noinfo
|
CVE-2020-0687
|
2024-11-21 13:54 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210493
|
7.2 |
HIGH
Network
|
sonatype
|
nexus
|
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
|
CWE-20
Improper Input Validation
|
CVE-2020-10204
|
2024-11-21 13:54 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210494
|
4.8 |
MEDIUM
Network
|
sonatype
|
nexus
|
Sonatype Nexus Repository before 3.21.2 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10203
|
2024-11-21 13:54 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210495
|
8.8 |
HIGH
Network
|
sonatype
|
nexus
|
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2020-10199
|
2024-11-21 13:54 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210496
|
6.5 |
MEDIUM
Network
|
zimbra
|
zm-mailbox
|
cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account. This differs from the intended behavior in which the domain of the…
|
CWE-862
Missing Authorization
|
CVE-2020-10194
|
2024-11-21 13:54 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210497
|
6.5 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 84.0.20 allows a webmail or demo account to delete arbitrary files (SEC-547).
|
NVD-CWE-noinfo
|
CVE-2020-10122
|
2024-11-21 13:54 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210498
|
9.8 |
CRITICAL
Network
|
cpanel
|
cpanel
|
cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546).
|
NVD-CWE-Other
|
CVE-2020-10121
|
2024-11-21 13:54 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210499
|
7.2 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545).
|
NVD-CWE-noinfo
|
CVE-2020-10120
|
2024-11-21 13:54 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210500
|
9.8 |
CRITICAL
Network
|
cpanel
|
cpanel
|
cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).
|
NVD-CWE-noinfo
|
CVE-2020-10119
|
2024-11-21 13:54 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|