CVE-2020-10000 to CVE-2020-10999
127 CVEs with public proof-of-concept exploits.
- CVE-2020-100051 PoCA resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1. An attacker in a…
- CVE-2020-100211 PoCOut-of-bounds write in USB Mass Storage with unaligned sizes
- CVE-2020-100231 PoCShell Subsystem Contains a Buffer Overflow Vulnerability In shell_spaces_trim
- CVE-2020-100241 PoCARM Platform Uses Signed Integer Comparison When Validating Syscall Numbers
- CVE-2020-100281 PoCMultiple Syscalls In GPIO Subsystem Performs No Argument Validation
- CVE-2020-100291 PoCThe GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long…
- CVE-2020-100571 PoCGeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for…
- CVE-2020-100631 PoCRemote Denial of Service in CoAP Option Parsing Due To Integer Overflow
- CVE-2020-100691 PoCZephyr Bluetooth unchecked packet data results in denial of service
- CVE-2020-101081 PoCIn Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it…
- CVE-2020-101091 PoCIn Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked…
- CVE-2020-101102 PoCsCitrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vulnerability. There…
- CVE-2020-101111 PoCCitrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests. NOTE: Citrix disputes the reported behavior as…
- CVE-2020-101121 PoCCitrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning. NOTE: Citrix disputes this as not a vulnerability. By default, Citrix ADC only…
- CVE-2020-101241 PoCNCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the…
- CVE-2020-101281 PoCSearchBlox product before V-9.2.1 is vulnerable to Stored-Cross Site Scripting
- CVE-2020-101291 PoCCVE-2020-10129
- CVE-2020-101301 PoCCVE-2020-10130
- CVE-2020-101311 PoCCVE-2020-10131
- CVE-2020-101321 PoCCVE-2020-10132
- CVE-2020-101353 PoCsBluetooth devices supporting BR/EDR v5.2 and earlier are vulnerable to impersonation attacks
- CVE-2020-101362 PoCsIP-in-IP protocol allows a remote, unauthenticated attacker to route arbitrary network traffic
- CVE-2020-101461 PoCMicrosoft Teams displayName stored cross-site scripting vulnerability
- CVE-2020-101487 PoCsKEVSolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
- CVE-2020-101731 PoCComtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping…
- CVE-2020-101812 PoCsKEVgoform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges…
- CVE-2020-101897 PoCsKEVZoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in…
- CVE-2020-1019915 PoCsKEVSonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
- CVE-2020-102047 PoCsSonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
- CVE-2020-102061 PoCUse of a Hard-coded Password in VNCserver in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx…
- CVE-2020-102071 PoCUse of Hard-coded Credentials in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series,…
- CVE-2020-102081 PoCCommand Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series…
- CVE-2020-102091 PoCCommand Injection in the CPE WAN Management Protocol (CWMP) registration in Amino Communications AK45x series, AK5xx series, AK65x series,…
- CVE-2020-102101 PoCBecause of hard-coded SSH keys for the root user in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series,…
- CVE-2020-102141 PoCAn issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is a stack-based buffer overflow in the httpd binary. It allows an…
- CVE-2020-102181 PoCA Blind SQL Injection issue was discovered in Sapplica Sentrifugo 3.2 via the index.php/holidaygroups/add id parameter because of the…
- CVE-2020-102205 PoCsAn issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn…
- CVE-2020-102214 PoCsKEVlib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell…
- CVE-2020-102221 PoCnpdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to Heap Corruption at npdf!nitro::get_property+2381 via a crafted PDF document.
- CVE-2020-102231 PoCnpdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at…
- CVE-2020-102241 PoCAn unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0. The vulnerability…
- CVE-2020-102251 PoCAn unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability…
- CVE-2020-102271 PoCA cross-site scripting (XSS) vulnerability in the messages module of vtecrm vtenext 19 CE allows attackers to inject arbitrary JavaScript…
- CVE-2020-102281 PoCA file upload vulnerability in vtecrm vtenext 19 CE allows authenticated users to upload files with a .pht extension, resulting in remote…
- CVE-2020-102291 PoCA CSRF issue in vtecrm vtenext 19 CE allows attackers to carry out unwanted actions on an administrator's behalf, such as uploading files,…
- CVE-2020-102301 PoCCentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php…
- CVE-2020-102313 PoCsTP-Link NC200 through 2.1.8_Build_171109, NC210 through 1.0.9_Build_171214, NC220 through 1.3.0_Build_180105, NC230 through…
- CVE-2020-102331 PoCIn version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfs_dinode_lookup in fs/ntfs.c.
- CVE-2020-102341 PoCThe AscRegistryFilter.sys kernel driver in IObit Advanced SystemCare 13.2 allows an unprivileged user to send an IOCTL to the device…
- CVE-2020-102351 PoCAn issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary…
- CVE-2020-102381 PoCAn issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various…
- CVE-2020-102391 PoCAn issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for…
- CVE-2020-102451 PoCCODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.
- CVE-2020-102481 PoCBWA DiREX-Pro 1.2181 devices allow remote attackers to discover passwords via a direct request to val_users.php3.
- CVE-2020-102491 PoCBWA DiREX-Pro 1.2181 devices allow full path disclosure via an invalid name array parameter to val_soft.php3.
- CVE-2020-102501 PoCBWA DiREX-Pro 1.2181 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the PKG parameter to…
- CVE-2020-102511 PoCIn ImageMagick 7.0.9, an out-of-bounds read vulnerability exists within the ReadHEICImageByID function in coders\heic.c. It can be…
- CVE-2020-102572 PoCsThe ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint,…
- CVE-2020-102622 PoCsAn issue was discovered on XIAOMI XIAOAI speaker Pro LX06 1.58.10. Attackers can activate the failsafe mode during the boot process, and…
- CVE-2020-102632 PoCsAn issue was discovered on XIAOMI XIAOAI speaker Pro LX06 1.52.4. Attackers can get root shell by accessing the UART interface and then…
- CVE-2020-102831 PoCRVD#3317: MAVLink version handshaking allows for an attacker to bypass authentication
- CVE-2020-103642 PoCsThe SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusal of new…
- CVE-2020-103651 PoCLogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the database. This list…
- CVE-2020-103661 PoCLogicalDoc before 8.3.3 allows /servlet.gupld Directory Traversal, a different vulnerability than CVE-2020-9423 and CVE-2020-10365.
- CVE-2020-103751 PoCAn issue was discovered in New Media Smarty before 9.10. Passwords are stored in the database in an obfuscated format that can be easily…
- CVE-2020-103853 PoCsA stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.
- CVE-2020-103862 PoCsadmin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by…
- CVE-2020-103871 PoCPath Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server…
- CVE-2020-103892 PoCsadmin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by injecting PHP code…
- CVE-2020-105322 PoCsThe AD Helper component in WatchGuard Fireware before 5.8.5.10317 allows remote attackers to discover cleartext passwords via the…
- CVE-2020-105461 PoCrConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords…
- CVE-2020-105471 PoCrConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes'…
- CVE-2020-105481 PoCrConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in…
- CVE-2020-105491 PoCrConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored…
- CVE-2020-105511 PoCQQBrowser before 10.5.3870.400 installs a Windows service TsService.exe. This file is writable by anyone belonging to the NT…
- CVE-2020-105584 PoCsThe driving interface of Tesla Model 3 vehicles in any release before 2020.4.10 allows Denial of Service to occur due to improper process…
- CVE-2020-105602 PoCsAn issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak cryptographic rand() can…
- CVE-2020-105641 PoCAn issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by…
- CVE-2020-105672 PoCsAn issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter,…
- CVE-2020-105681 PoCThe sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code…
- CVE-2020-105691 PoCSysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additionally, it allows…
- CVE-2020-105961 PoCOpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section.
- CVE-2020-106441 PoCThe affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition…
- CVE-2020-106501 PoCA deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code…
- CVE-2020-106631 PoCThe JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object…
- CVE-2020-106651 PoCDocker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnostics with…
- CVE-2020-106691 PoCThe web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to authentication bypass on the page /home.jsp.…
- CVE-2020-106732 PoCsFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to…
- CVE-2020-107491 PoCA vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in…
- CVE-2020-107571 PoCA flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker…
- CVE-2020-107592 PoCsA PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream,…
- CVE-2020-107705 PoCsA flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC…
- CVE-2020-108085 PoCsVesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint. The attacker must…
- CVE-2020-108092 PoCsAn issue was discovered in HDF5 through 1.12.0. A heap-based buffer overflow exists in the function Decompress() located in decompress.c.…
- CVE-2020-108102 PoCsAn issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5AC_unpin_entry() located in H5AC.c. It…
- CVE-2020-108112 PoCsAn issue was discovered in HDF5 through 1.12.0. A heap-based buffer over-read exists in the function H5O__layout_decode() located in…
- CVE-2020-108122 PoCsAn issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5F_get_nrefs() located in H5Fquery.c.…
- CVE-2020-108131 PoCA buffer overflow vulnerability in FTPDMIN 0.96 allows attackers to crash the server via a crafted packet.
- CVE-2020-108181 PoCArtica Proxy 4.26 allows remote command execution for an authenticated user via shell metacharacters in the "Modify the hostname" field.
- CVE-2020-108191 PoCNagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ username parameter.
- CVE-2020-108201 PoCNagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ password parameter.
- CVE-2020-108211 PoCNagios XI 5.6.11 allows XSS via the account/main.php theme parameter.
- CVE-2020-108231 PoCA stack-based buffer overflow in /cgi-bin/activate.cgi through var parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before…
- CVE-2020-108241 PoCA stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices…
- CVE-2020-108251 PoCA stack-based buffer overflow in /cgi-bin/activate.cgi while base64 decoding ticket parameter on Draytek Vigor3900, Vigor2960, and…
- CVE-2020-108261 PoC/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command…
- CVE-2020-108271 PoCA stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to…
- CVE-2020-108281 PoCA stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to…
- CVE-2020-108741 PoCMotorola FX9500 devices allow remote attackers to read database files.
- CVE-2020-108751 PoCMotorola FX9500 devices allow remote attackers to conduct absolute path traversal attacks, as demonstrated by PL/SQL Server Pages files…
- CVE-2020-108791 PoCrConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is…
- CVE-2020-108811 PoCThis vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726…
- CVE-2020-108824 PoCsThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware…
- CVE-2020-108833 PoCsThis vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware Ver: 190726…
- CVE-2020-108843 PoCsThis vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver:…
- CVE-2020-109141 PoCThis vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587.…
- CVE-2020-109152 PoCsThis vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587.…
- CVE-2020-109311 PoCMemcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to…
- CVE-2020-109351 PoCZulip Server before 2.1.3 allows XSS via a Markdown link, with resultant account takeover.
- CVE-2020-109632 PoCsFrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via…
- CVE-2020-109731 PoCAn issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh…
- CVE-2020-1097713 PoCsGitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.
- CVE-2020-109821 PoCGambio GX before 4.0.1.0 allows SQL Injection in admin/gv_mail.php.
- CVE-2020-109831 PoCGambio GX before 4.0.1.0 allows SQL Injection in admin/mobile.php.
- CVE-2020-109841 PoCGambio GX before 4.0.1.0 allows admin/admin.php CSRF.
- CVE-2020-109851 PoCGambio GX before 4.0.1.0 allows XSS in admin/coupon_admin.php.
- CVE-2020-109871 PoCKEVThe goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via…