|
208701
|
7.8 |
HIGH
Local
|
163
|
netease_mail_master
|
Guangzhou NetEase Mail Master 4.14.1.1004 on Windows has a DLL hijacking vulnerability. Attackers can use this vulnerability to execute malicious code.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-24161
|
2024-11-21 14:14 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208702
|
7.8 |
HIGH
Local
|
tencent
|
tim
|
Shenzhen Tencent TIM Windows client 3.0.0.21315 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-24160
|
2024-11-21 14:14 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208703
|
7.8 |
HIGH
Local
|
163
|
netease_youdao_dictionary
|
NetEase Youdao Dictionary has a DLL hijacking vulnerability, which can be exploited by attackers to gain server permissions. This affects Guangzhou NetEase Youdao Dictionary 8.9.2.0.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-24159
|
2024-11-21 14:14 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208704
|
7.8 |
HIGH
Local
|
360
|
speed_browser
|
360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code. It is a dual-core browser owned by Beijing Qihoo Technology.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-24158
|
2024-11-21 14:14 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208705
|
6.1 |
MEDIUM
Network
|
xuxueli
|
xxl-job
|
Multiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) AppName and (2)AddressList parameter in JobGroupController.…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23814
|
2024-11-21 14:14 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208706
|
7.5 |
HIGH
Network
|
xuxueli
|
xxl-job
|
xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.java.
|
NVD-CWE-noinfo
|
CVE-2020-23811
|
2024-11-21 14:14 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208707
|
5.5 |
MEDIUM
Local
|
midnightbsd freebsd
|
midnightbsd freebsd
|
In MidnightBSD before 1.2.6 and 1.3 before August 2020, and FreeBSD before 7, a NULL pointer dereference was found in the Linux emulation layer that allows attackers to crash the running kernel. Duri…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-24385
|
2024-11-21 14:14 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208708
|
6.1 |
MEDIUM
Network
|
golang fedoraproject opensuse oracle
|
go fedora leap communications_cloud_native_core_policy
|
Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a Content-Type header.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24553
|
2024-11-21 14:14 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208709
|
9.8 |
CRITICAL
Network
|
forlogic
|
qualiex
|
ForLogic Qualiex v1 and v3 has weak token expiration. This allows remote unauthenticated privilege escalation and access to sensitive data via token reuse.
|
CWE-672
Operation on a Resource after Expiration or Release
|
CVE-2020-24030
|
2024-11-21 14:14 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208710
|
9.8 |
CRITICAL
Network
|
forlogic
|
qualiex
|
Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can be accessed via a simple request.
|
CWE-287
Improper Authentication
|
CVE-2020-24029
|
2024-11-21 14:14 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|