|
211401
|
7.8 |
HIGH
Local
|
bbraun
|
onlinesuite_application_package
|
An Excel Macro Injection vulnerability exists in the export feature in the B. Braun OnlineSuite Version AP 3.0 and earlier via multiple input fields that are mishandled in an Excel export.
|
-
|
CVE-2020-25170
|
2024-11-21 14:17 |
2020-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211402
|
7.8 |
HIGH
Local
|
mind
|
imind_server
|
Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chat.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25399
|
2024-11-21 14:17 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211403
|
8.8 |
HIGH
Network
|
mind
|
imind_server
|
CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-25398
|
2024-11-21 14:17 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211404
|
7.5 |
HIGH
Network
|
hashicorp
|
consul
|
HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes. Fixed in 1.7.9 and 1.8.5.
|
NVD-CWE-noinfo
|
CVE-2020-25201
|
2024-11-21 14:17 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211405
|
2.6 |
LOW
Network
|
cyberark
|
privileged_session_manager
|
CyberArk Privileged Session Manager (PSM) 10.9.0.15 allows attackers to discover internal pathnames by reading an error popup message after two hours of idle time.
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-25374
|
2024-11-21 14:17 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211406
|
5.5 |
MEDIUM
Local
|
innogames
|
god_kings
|
The God Kings application 0.60.1 for Android exposes a broadcast receiver to other apps called com.innogames.core.frontend.notifications.receivers.LocalNotificationBroadcastReceiver. The purpose of t…
|
NVD-CWE-Other
|
CVE-2020-25204
|
2024-11-21 14:17 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211407
|
7.5 |
HIGH
Network
|
we-con
|
levistudiou
|
An XXE vulnerability exists within LeviStudioU Release Build 2019-09-21 and prior when processing parameter entities, which may allow file disclosure.
|
CWE-611
XXE
|
CVE-2020-25186
|
2024-11-21 14:17 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211408
|
7.5 |
HIGH
Network
|
advantech
|
r-seenet
|
The R-SeeNet webpage (1.5.1 through 2.4.10) suffers from SQL injection, which allows a remote attacker to invoke queries on the database and retrieve sensitive information.
|
CWE-89
SQL Injection
|
CVE-2020-25157
|
2024-11-21 14:17 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211409
|
8.1 |
HIGH
Network
|
overwolf
|
overwolf
|
In the client in Overwolf 0.149.2.30, a channel can be accessed or influenced by an actor that is not an endpoint.
|
NVD-CWE-Other
|
CVE-2020-25214
|
2024-11-21 14:17 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211410
|
7.8 |
HIGH
Local
|
laquisscada
|
scada
|
An attacker who convinces a valid user to open a specially crafted project file to exploit could execute code under the privileges of the application due to an out-of-bounds read vulnerability on the…
|
-
|
CVE-2020-25188
|
2024-11-21 14:17 |
2020-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|