|
198791
|
9.8 |
CRITICAL
Network
|
sage
|
adxadmin
|
Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential validation. While explo…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2020-7388
|
2024-11-21 14:37 |
2021-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198792
|
5.3 |
MEDIUM
Network
|
sage
|
adxadmin
|
Sage X3 Installation Pathname Disclosure. A specially crafted packet can elicit a response from the AdxDSrv.exe component that reveals the installation directory of the product. Note that this vulner…
|
NVD-CWE-noinfo
|
CVE-2020-7387
|
2024-11-21 14:37 |
2021-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198793
|
9.8 |
CRITICAL
Network
|
tobesoft
|
xplatform
|
When using XPLATFORM 9.2.2.270 or earlier versions ActiveX component, arbitrary commands can be executed due to improper input validation
|
CWE-20
Improper Input Validation
|
CVE-2020-7866
|
2024-11-21 14:37 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198794
|
7.8 |
HIGH
Local
|
hmtalk
|
daviewindy
|
DaviewIndy v8.98.7.0 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed format file that is mishandled by DaviewIndy. Attackers could exploit this a…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-7872
|
2024-11-21 14:37 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198795
|
7.2 |
HIGH
Network
|
unidocs
|
ezpdf_reader ezpdf_editor
|
A memory corruption vulnerability exists when ezPDF improperly handles the parameter. This vulnerability exists due to insufficient validation of the parameter.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7870
|
2024-11-21 14:37 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198796
|
8.8 |
HIGH
Network
|
mastersoft
|
zook
|
An improper input validation vulnerability of ZOOK software (remote administration tool) could allow a remote attacker to create arbitrary file. The ZOOK viewer has the "Tight file CMD" function to c…
|
CWE-20
Improper Input Validation
|
CVE-2020-7869
|
2024-11-21 14:37 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198797
|
9.8 |
CRITICAL
Network
|
helpu
|
helpu
|
A remote code execution vulnerability exists in helpUS(remote administration tool) due to improper validation of parameter of ShellExecutionExA function used for login.
|
NVD-CWE-Other
|
CVE-2020-7868
|
2024-11-21 14:37 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198798
|
9.8 |
CRITICAL
Network
|
cnesty
|
helpcom
|
A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient validation of the parameter. This issue affects: Cnesty …
|
CWE-20
Improper Input Validation
|
CVE-2020-7871
|
2024-11-21 14:37 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198799
|
8.8 |
HIGH
Network
|
helpu
|
helpuviewer helpuserver helpuftclient helpuftserver
|
A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execute arbitrary commands This vulnerability is due to insufficient input santizatio…
|
CWE-20
Improper Input Validation
|
CVE-2020-7862
|
2024-11-21 14:37 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198800
|
9.8 |
CRITICAL
Network
|
dext5
|
dext5_editor
|
Parameter manipulation can bypass authentication to cause file upload and execution. This will execute the remote code. This issue affects: Raonwiz DEXT5Editor versions prior to 3.5.1405747.1100.03.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-7864
|
2024-11-21 14:37 |
2021-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|