|
209461
|
7.2 |
HIGH
Network
|
zohocorp
|
manageengine_desktop_central
|
An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.0.SP-534. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendR…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2020-24397
|
2024-11-21 14:14 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209462
|
7.8 |
HIGH
Local
|
cloudflare
|
cloudflared
|
`cloudflared` versions prior to 2020.8.1 contain a local privilege escalation vulnerability on Windows systems. When run on a Windows system, `cloudflared` searches for configuration files which coul…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-24356
|
2024-11-21 14:14 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209463
|
7.8 |
HIGH
Local
|
trendmicro
|
apex_one
|
A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unload option (if configured), which then could be manipulated to gain a privilege e…
|
CWE-287
Improper Authentication
|
CVE-2020-24563
|
2024-11-21 14:14 |
2020-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209464
|
7.8 |
HIGH
Local
|
trendmicro
|
officescan
|
A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escala…
|
CWE-59
Link Following
|
CVE-2020-24562
|
2024-11-21 14:14 |
2020-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209465
|
8.8 |
HIGH
Network
|
multi_user_project
|
multi_user
|
A Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attackers to add admin (or other) users after an authenticated admin visits a third-pa…
|
CWE-352
Origin Validation Error
|
CVE-2020-23837
|
2024-11-21 14:14 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209466
|
8.8 |
HIGH
Network
|
gemteks
|
wrtm-127acn_firmware wrtm-127x9_firmware
|
An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on t…
|
CWE-78 CWE-1188
OS Command Insecure Default Initialization of Resource
|
CVE-2020-24365
|
2024-11-21 14:14 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209467
|
7.5 |
HIGH
Network
|
trendmicro
|
antivirus\+_2019 internet_security_2019 maximum_security_2019 officescan_cloud premium_security_2019
|
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another a…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-24560
|
2024-11-21 14:14 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209468
|
7.5 |
HIGH
Network
|
ygopro
|
ygocore
|
An integer overflow was discovered in YGOPro ygocore v13.51. Attackers can use it to leak the game server thread's memory.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-24213
|
2024-11-21 14:14 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209469
|
6.5 |
MEDIUM
Network
|
arista
|
cloudvision_portal
|
A vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rights to the Configlet Management module to download files not intended for acces…
|
NVD-CWE-noinfo
|
CVE-2020-24333
|
2024-11-21 14:14 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209470
|
7.2 |
HIGH
Network
|
titanhq
|
spamtitan
|
A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. This re…
|
CWE-269
Improper Privilege Management
|
CVE-2020-24046
|
2024-11-21 14:14 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|