|
210401
|
8.8 |
HIGH
Network
|
connectwise
|
automate
|
The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-15838
|
2024-11-21 14:06 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210402
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_applications_manager
|
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module.
|
CWE-89
SQL Injection
|
CVE-2020-15927
|
2024-11-21 14:06 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210403
|
9.8 |
CRITICAL
Network
|
mitsubishielectric
|
qj71mes96_firmware qj71ws96_firmware q06ccpu-v_firmware q24dhccpu-v_firmware q24dhccpu-vg_firmware r12ccpu-v_firmware rd55up06-v_firmware rd55up12-v_firmware rj71gn11-t2_firmw…
|
Multiple Mitsubishi Electric products are vulnerable to impersonations of a legitimate device by a malicious actor, which may allow an attacker to remotely execute arbitrary commands.
|
-
|
CVE-2020-16226
|
2024-11-21 14:06 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210404
|
7.8 |
HIGH
Local
|
fatek
|
winproladder
|
In PLC WinProladder Version 3.28 and prior, a stack-based buffer overflow vulnerability can be exploited when a valid user opens a specially crafted file, which may allow an attacker to remotely exec…
|
-
|
CVE-2020-16234
|
2024-11-21 14:06 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210405
|
7.2 |
HIGH
Network
|
re-desk
|
re\
|
Re:Desk 2.3 has a blind authenticated SQL injection vulnerability in the SettingsController class, in the actionEmailTemplates() method. A malicious actor with access to an administrative account cou…
|
CWE-89
SQL Injection
|
CVE-2020-15849
|
2024-11-21 14:06 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210406
|
3.6 |
LOW
Local
|
bitdefender
|
engines
|
An improper Input Validation vulnerability in the code handling file renaming and recovery in Bitdefender Engines allows an attacker to write an arbitrary file in a location hardcoded in a specially-…
|
CWE-20
Improper Input Validation
|
CVE-2020-15731
|
2024-11-21 14:06 |
2020-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210407
|
7.3 |
HIGH
Local
|
actfax
|
actfax
|
ActFax Version 7.10 Build 0335 (2020-05-25) is susceptible to a privilege escalation vulnerability due to insecure folder permissions on %PROGRAMFILES%\ActiveFax\Client\, %PROGRAMFILES%\ActiveFax\Ins…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-15843
|
2024-11-21 14:06 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210408
|
9.8 |
CRITICAL
Network
|
nakivo
|
backup_\&_replication_transporter
|
Lack of access control in Nakivo Backup & Replication Transporter version 9.4.0.r43656 allows remote users to access unencrypted backup repositories and the Nakivo Controller configuration via a netw…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-15851
|
2024-11-21 14:06 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210409
|
7.8 |
HIGH
Local
|
nakivo
|
backup_\&_replication_director
|
Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access the Nakivo Director web interface and gain root privileges. This occurs because …
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-15850
|
2024-11-21 14:06 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210410
|
6.1 |
MEDIUM
Network
|
joplin_project
|
joplin
|
An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15930
|
2024-11-21 14:06 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|