|
212201
|
7.8 |
HIGH
Local
|
dreamreport
|
dream_report
|
A privilege escalation vulnerability exists in Dream Report 5 R20-2. COM Class Identifiers (CLSID), installed by Dream Report 5 20-2, reference LocalServer32 and InprocServer32 with weak privileges w…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13534
|
2024-11-21 14:01 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212202
|
7.8 |
HIGH
Local
|
dreamreport
|
dream_report
|
A privilege escalation vulnerability exists in Dream Report 5 R20-2. IIn the default configuration, the following registry keys, which reference binaries with weak permissions, can be abused by attac…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13533
|
2024-11-21 14:01 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212203
|
7.8 |
HIGH
Local
|
dreamreport
|
dream_report
|
A privilege escalation vulnerability exists in Dream Report 5 R20-2. In the default configuration, the Syncfusion Dashboard Service service binary can be replaced by attackers to escalate privileges …
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13532
|
2024-11-21 14:01 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212204
|
8.1 |
HIGH
Network
|
openiam
|
openiam
|
OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions.
|
CWE-862
Missing Authorization
|
CVE-2020-13422
|
2024-11-21 14:01 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212205
|
9.8 |
CRITICAL
Network
|
openiam
|
openiam
|
OpenIAM before 4.2.0.3 has Incorrect Access Control for the Create User, Modify User Permissions, and Password Reset actions.
|
NVD-CWE-Other
|
CVE-2020-13421
|
2024-11-21 14:01 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212206
|
9.8 |
CRITICAL
Network
|
openiam
|
openiam
|
OpenIAM before 4.2.0.3 allows remote attackers to execute arbitrary code via Groovy Script.
|
NVD-CWE-noinfo
|
CVE-2020-13420
|
2024-11-21 14:01 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212207
|
5.3 |
MEDIUM
Network
|
openiam
|
openiam
|
OpenIAM before 4.2.0.3 allows Directory Traversal in the Batch task.
|
CWE-22
Path Traversal
|
CVE-2020-13419
|
2024-11-21 14:01 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212208
|
6.1 |
MEDIUM
Network
|
openiam
|
openiam
|
OpenIAM before 4.2.0.3 allows XSS in the Add New User feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13418
|
2024-11-21 14:01 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212209
|
8.8 |
HIGH
Network
|
webkitgtk
|
webkitgtk
|
A code execution vulnerability exists in the AudioSourceProviderGStreamer functionality of Webkit WebKitGTK 2.30.1. A specially crafted web page can lead to a use after free.
|
CWE-416
Use After Free
|
CVE-2020-13558
|
2024-11-21 14:01 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212210
|
7.8 |
HIGH
Local
|
advantech
|
webaccess\/scada
|
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation …
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13554
|
2024-11-21 14:01 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|