|
209391
|
6.1 |
MEDIUM
Network
|
adobe
|
connect
|
Adobe Connect version 11.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page,…
|
-
|
CVE-2020-24442
|
2024-11-21 14:14 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209392
|
5.5 |
MEDIUM
Local
|
adobe
|
acrobat_reader
|
Adobe Acrobat Reader for Android version 20.6.2 (and earlier) does not properly restrict access to directories created by the application. This could result in disclosure of sensitive information sto…
|
NVD-CWE-Other
|
CVE-2020-24441
|
2024-11-21 14:14 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209393
|
7.8 |
HIGH
Local
|
bluestacks
|
bluestacks
|
Incorrect file permissions in BlueStacks 4 through 4.230 on Windows allow a local attacker to escalate privileges by modifying a file that is later executed by a higher-privileged user.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-24367
|
2024-11-21 14:14 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209394
|
7.2 |
HIGH
Network
|
canto
|
canto
|
The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-24063
|
2024-11-21 14:14 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209395
|
7.8 |
HIGH
Local
|
ilex
|
international_sign\&go
|
Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\Ilex\S&G\Logs\000-sngWSService1.log.
|
CWE-59
Link Following
|
CVE-2020-23968
|
2024-11-21 14:14 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209396
|
9.8 |
CRITICAL
Network
|
a10networks
|
agalaxy advanced_core_operating_system
|
A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Code Execution (RCE) vulnerability that could be used to compromise affected ACOS systems. ACO…
|
NVD-CWE-noinfo
|
CVE-2020-24384
|
2024-11-21 14:14 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209397
|
6.1 |
MEDIUM
Network
|
pega
|
pega_platform
|
Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24353
|
2024-11-21 14:14 |
2020-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209398
|
9.1 |
CRITICAL
Network
|
magento
|
magento
|
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. This vulnerability could be abused by authenticated…
|
-
|
CVE-2020-24407
|
2024-11-21 14:14 |
2020-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209399
|
3.7 |
LOW
Network
|
magento
|
magento
|
When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affected by an information disclosure vulnerability that could expose the installation path during build deployments. This …
|
CWE-22
Path Traversal
|
CVE-2020-24406
|
2024-11-21 14:14 |
2020-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209400
|
4.3 |
MEDIUM
Network
|
magento
|
magento
|
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inventory module. This vulnerability could be abused by authenticated users to modi…
|
NVD-CWE-Other
|
CVE-2020-24405
|
2024-11-21 14:14 |
2020-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|