|
210371
|
8.8 |
HIGH
Local
|
win911
|
mobile-911_server
|
An exploitable local privilege elevation vulnerability exists in the file system permissions of the Mobile-911 Server V2.5 install directory. Depending on the vector chosen, an attacker can overwrite…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13541
|
2024-11-21 14:01 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210372
|
7.8 |
HIGH
Local
|
win911
|
win-911
|
An exploitable local privilege elevation vulnerability exists in the file system permissions of the Win-911 Enterprise V4.20.13 install directory via WIN-911 Account Change Utility. Depending on the …
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13540
|
2024-11-21 14:01 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210373
|
7.8 |
HIGH
Local
|
win911
|
win-911
|
An exploitable local privilege elevation vulnerability exists in the file system permissions of the Win-911 Enterprise V4.20.13 install directory via “WIN-911 Mobile Runtime” service. Depending on th…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13539
|
2024-11-21 14:01 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210374
|
7.5 |
HIGH
Network
|
xwiki
|
xwiki
|
XWiki Platform before 12.8 mishandles escaping in the property displayer.
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2020-13654
|
2024-11-21 14:01 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210375
|
4.8 |
MEDIUM
Network
|
nchsoftware
|
express_invoice
|
NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13476
|
2024-11-21 14:01 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210376
|
6.5 |
MEDIUM
Network
|
nchsoftware
|
express_accounts
|
In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2020-13474
|
2024-11-21 14:01 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210377
|
5.5 |
MEDIUM
Local
|
nchsoftware
|
express_accounts
|
NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-13473
|
2024-11-21 14:01 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210378
|
8.8 |
HIGH
Network
|
foxitsoftware
|
foxit_reader
|
A type confusion vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger an improper use of an object, r…
|
CWE-787 CWE-843
Out-of-bounds Write Type Confusion
|
CVE-2020-13547
|
2024-11-21 14:01 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210379
|
8.8 |
HIGH
Network
|
foxitsoftware
|
foxit_reader
|
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger the reuse of previously free memory w…
|
CWE-416
Use After Free
|
CVE-2020-13570
|
2024-11-21 14:01 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210380
|
8.8 |
HIGH
Network
|
foxitsoftware
|
foxit_reader
|
A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of previously free memory…
|
CWE-416
Use After Free
|
CVE-2020-13560
|
2024-11-21 14:01 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|