|
196911
|
8.8 |
HIGH
Network
|
tobesoft
|
nexacro
|
Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of tobesoft Co., Ltd allows the attacker to cause an arbitrary file download and execution. This vulnerabil…
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-7874
|
2024-11-21 14:37 |
2021-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196912
|
9.8 |
CRITICAL
Network
|
ksystem
|
k-system_wellcomm
|
Download of code without integrity check vulnerability in ActiveX control of Younglimwon Co., Ltd allows the attacker to cause a arbitrary file download and execution.
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-7873
|
2024-11-21 14:37 |
2021-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196913
|
9.8 |
CRITICAL
Network
|
inoguard
|
execm_coreb2b
|
A vulnerability(improper input validation) in the ExECM CoreB2B solution allows an unauthenticated attacker to download and execute an arbitrary file via httpDownload function. A successful exploit c…
|
CWE-20
Improper Input Validation
|
CVE-2020-7865
|
2024-11-21 14:37 |
2021-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196914
|
9.8 |
CRITICAL
Network
|
dext5
|
dext5
|
A vulnerability (improper input validation) in the DEXT5 Upload solution allows an unauthenticated attacker to download and execute an arbitrary file via AddUploadFile, SetSelectItem, DoOpenFile func…
|
CWE-20
Improper Input Validation
|
CVE-2020-7832
|
2024-11-21 14:37 |
2021-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196915
|
7.5 |
HIGH
Network
|
ntracker
|
ntracker_usb_enterprise
|
A SQL-Injection vulnerability in the nTracker USB Enterprise(secure USB management solution) allows a remote unauthenticated attacker to perform SQL query to access username password and other sessio…
|
CWE-89
SQL Injection
|
CVE-2020-7819
|
2024-11-21 14:37 |
2021-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196916
|
8.8 |
HIGH
Network
|
mastersoft
|
zook_agent zook_viewer
|
A buffer overflow issue was discovered in ZOOK solution(remote administration tool) through processing 'ConnectMe' command while parsing a crafted OUTERIP value because of missing boundary check. Thi…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-7877
|
2024-11-21 14:37 |
2021-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196917
|
8.8 |
HIGH
Network
|
raonwiz
|
raon_k_upload
|
A vulnerability in File Transfer Solution of Raonwiz could allow arbitrary command execution as the result of viewing a specially-crafted web page. This vulnerability is due to insufficient validatio…
|
CWE-20
Improper Input Validation
|
CVE-2020-7863
|
2024-11-21 14:37 |
2021-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196918
|
5.4 |
MEDIUM
Network
|
sage
|
syracuse
|
Sage X3 Stored XSS Vulnerability on ‘Edit’ Page of User Profile. An authenticated user can pass XSS strings the "First Name," "Last Name," and "Email Address" fields of this web application component…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7390
|
2024-11-21 14:37 |
2021-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196919
|
7.2 |
HIGH
Network
|
sage
|
syracuse
|
Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configura…
|
CWE-78
OS Command
|
CVE-2020-7389
|
2024-11-21 14:37 |
2021-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196920
|
9.8 |
CRITICAL
Network
|
sage
|
adxadmin
|
Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential validation. While explo…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2020-7388
|
2024-11-21 14:37 |
2021-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|