|
196311
|
7.8 |
HIGH
Local
|
honeywell
|
inncom_inncontrol_firmware
|
Honeywell INNCOM INNControl 3 allows workstation users to escalate application user privileges through the modification of local configuration files.
|
CWE-269
Improper Privilege Management
|
CVE-2020-6968
|
2024-11-21 14:36 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196312
|
6.8 |
MEDIUM
Physics
|
ge
|
vivid_e95_firmware vivid_e90_firmware vivid_s70n_firmware vivid_t8_firmware vivid_t9_firmware vivid_iq_firmware logiq_e10_firmware logiq_e9_firmware logiq_s8_firmware logiq…
|
A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow the user to escape the restricted environment, res…
|
CWE-20 NVD-CWE-Other
Improper Input Validation
|
CVE-2020-6977
|
2024-11-21 14:36 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196313
|
9.8 |
CRITICAL
Network
|
emerson
|
openenterprise_scada_server
|
A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterprise 3.1 through 3.3.…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6970
|
2024-11-21 14:36 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196314
|
6.1 |
MEDIUM
Network
|
topmanage
|
olk_webstore
|
An issue was discovered in TopManage OLK 2020. As there is no ReadOnly on the Session cookie, the user and admin accounts can be taken over in a DOM-Based XSS attack.
|
CWE-79
Cross-site Scripting
|
CVE-2020-6845
|
2024-11-21 14:36 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196315
|
8.8 |
HIGH
Network
|
topmanage
|
olk_webstore
|
In TopManage OLK 2020, login CSRF can be chained with another vulnerability in order to takeover admin and user accounts.
|
CWE-352
Origin Validation Error
|
CVE-2020-6844
|
2024-11-21 14:36 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196316
|
6.1 |
MEDIUM
Network
|
miniorange
|
saml_sp_single_sign_on
|
Utilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML XML Response to wp-login.php. This is related to the SAMLResponse and RelayStat…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6850
|
2024-11-21 14:36 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196317
|
5.5 |
MEDIUM
Local
|
mcafee
|
data_exchange_layer
|
Unquoted service executable path in DXL Broker in McAfee Data eXchange Layer (DXL) Framework 6.0.0 and earlier allows local users to cause a denial of service and malicious file execution via careful…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2020-7252
|
2024-11-21 14:36 |
2020-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196318
|
5.4 |
MEDIUM
Network
|
codologic
|
codoforum
|
Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to add a poll that is automatically loaded in the DOM once the thread/topic is op…
|
CWE-79 CWE-732
Cross-site Scripting Incorrect Permission Assignment for Critical Resource
|
CVE-2020-7050
|
2024-11-21 14:36 |
2020-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196319
|
5.5 |
MEDIUM
Local
|
mcafee
|
endpoint_security
|
Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows local users to disable security features via unauthori…
|
CWE-863
Incorrect Authorization
|
CVE-2020-7251
|
2024-11-21 14:36 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196320
|
6.1 |
MEDIUM
Network
|
codologic
|
codoforum
|
Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because session cookies lack the HttpOnly flag. The impact is account takeove…
|
CWE-79 CWE-732
Cross-site Scripting Incorrect Permission Assignment for Critical Resource
|
CVE-2020-7051
|
2024-11-21 14:36 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|