|
208601
|
7.8 |
HIGH
Local
|
bluestacks
|
bluestacks
|
Incorrect file permissions in BlueStacks 4 through 4.230 on Windows allow a local attacker to escalate privileges by modifying a file that is later executed by a higher-privileged user.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-24367
|
2024-11-21 14:14 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208602
|
7.2 |
HIGH
Network
|
canto
|
canto
|
The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-24063
|
2024-11-21 14:14 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208603
|
7.8 |
HIGH
Local
|
ilex
|
international_sign\&go
|
Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\Ilex\S&G\Logs\000-sngWSService1.log.
|
CWE-59
Link Following
|
CVE-2020-23968
|
2024-11-21 14:14 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208604
|
9.8 |
CRITICAL
Network
|
a10networks
|
agalaxy advanced_core_operating_system
|
A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Code Execution (RCE) vulnerability that could be used to compromise affected ACOS systems. ACO…
|
NVD-CWE-noinfo
|
CVE-2020-24384
|
2024-11-21 14:14 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208605
|
6.1 |
MEDIUM
Network
|
pega
|
pega_platform
|
Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24353
|
2024-11-21 14:14 |
2020-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208606
|
9.1 |
CRITICAL
Network
|
magento
|
magento
|
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. This vulnerability could be abused by authenticated…
|
-
|
CVE-2020-24407
|
2024-11-21 14:14 |
2020-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208607
|
3.7 |
LOW
Network
|
magento
|
magento
|
When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affected by an information disclosure vulnerability that could expose the installation path during build deployments. This …
|
CWE-22
Path Traversal
|
CVE-2020-24406
|
2024-11-21 14:14 |
2020-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208608
|
4.3 |
MEDIUM
Network
|
magento
|
magento
|
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inventory module. This vulnerability could be abused by authenticated users to modi…
|
NVD-CWE-Other
|
CVE-2020-24405
|
2024-11-21 14:14 |
2020-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208609
|
2.7 |
LOW
Network
|
magento
|
magento
|
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integrations component. This vulnerability could be abused by users with permissions …
|
NVD-CWE-Other
|
CVE-2020-24404
|
2024-11-21 14:14 |
2020-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208610
|
2.7 |
LOW
Network
|
magento
|
magento
|
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users w…
|
NVD-CWE-Other
|
CVE-2020-24403
|
2024-11-21 14:14 |
2020-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|