CVE-2020-12000 to CVE-2020-12999
121 CVEs with public proof-of-concept exploits.
- CVE-2020-120041 PoCThe affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior to 8.0.10) and…
- CVE-2020-120271 PoCRockwell Automation FactoryTalk View SE
- CVE-2020-120282 PoCsRockwell Automation FactoryTalk View SE
- CVE-2020-120292 PoCsRockwell Automation FactoryTalk View SE
- CVE-2020-120492 PoCsAn issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a…
- CVE-2020-120542 PoCsThe Catch Breadcrumb plugin before 1.5.4 for WordPress allows Reflected XSS via the s parameter (a search query). Also affected are 16…
- CVE-2020-120611 PoCAn issue was discovered in Nitrokey FIDO U2F firmware through 1.1. Communication between the microcontroller and the secure element…
- CVE-2020-120741 PoCThe users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative…
- CVE-2020-120771 PoCThe mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or…
- CVE-2020-120784 PoCsAn issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/configuration/ URI. An…
- CVE-2020-120801 PoCA Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.16.6. A certain message protocol can…
- CVE-2020-121013 PoCsThe address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by…
- CVE-2020-121093 PoCsCertain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build…
- CVE-2020-121101 PoCCertain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build…
- CVE-2020-121111 PoCCertain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304.
- CVE-2020-121121 PoCBigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.
- CVE-2020-121162 PoCsZoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read…
- CVE-2020-121201 PoCThe Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such as a service's…
- CVE-2020-121221 PoCIn Max Secure Max Spyware Detector 1.0.0.044, the driver file (MaxProc64.sys) allows local users to cause a denial of service (BSOD) or…
- CVE-2020-121243 PoCsA remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an…
- CVE-2020-121271 PoCAn information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an…
- CVE-2020-121281 PoCDONG JOO CHO File Transfer iFamily 2.1 allows directory traversal related to the ./etc/ path.
- CVE-2020-121291 PoCThe AirDisk Pro app 5.5.3 for iOS allows XSS via the createFolder parameter of the Create Folder function.
- CVE-2020-121301 PoCThe AirDisk Pro app 5.5.3 for iOS allows XSS via the deleteFile parameter of the Delete function.
- CVE-2020-121311 PoCThe AirDisk Pro app 5.5.3 for iOS allows XSS via the devicename parameter (shown next to the UI logo).
- CVE-2020-121331 PoCThe Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of…
- CVE-2020-121341 PoCNanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log.
- CVE-2020-121381 PoCAMD ATI atillk64.sys 5.11.9.0 allows low-privileged users to interact directly with physical memory by calling one of several driver…
- CVE-2020-121401 PoCA buffer overflow in os/net/mac/ble/ble-l2cap.c in the BLE stack in Contiki-NG 4.4 and earlier allows an attacker to execute arbitrary…
- CVE-2020-121451 PoCSilver Peak Unity OrchestratorTM authentication can be subverted through manipulation of HTTP headers.
- CVE-2020-122421 PoCValve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a…
- CVE-2020-122463 PoCsBeeline Smart Box 2.0.38 routers allow "Advanced settings > Other > Diagnostics" OS command injection via the Ping ping_ipaddr parameter,…
- CVE-2020-122551 PoCrConfig 3.9.4 is vulnerable to remote code execution due to improper validation in the file upload functionality. vendor.crud.php accepts…
- CVE-2020-122561 PoCrConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by…
- CVE-2020-122591 PoCrConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this…
- CVE-2020-122612 PoCsOpen-AudIT 3.3.0 allows an XSS attack after login.
- CVE-2020-122623 PoCsIntelbras TIP200 60.61.75.15, TIP200LITE 60.61.75.15, and TIP300 65.61.75.15 devices allow /cgi-bin/cgiServer.exx?page= XSS.
- CVE-2020-122652 PoCsThe decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when a symlink is…
- CVE-2020-122711 PoCKEVA SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the…
- CVE-2020-122721 PoCOpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that…
- CVE-2020-122801 PoCiSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to open/close a specified garage door/gate via /isg/opendoor.php.
- CVE-2020-122811 PoCiSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to create a new user via /index.php.
- CVE-2020-122821 PoCiSmartgate PRO 1.5.9 is vulnerable to CSRF via the busca parameter in the form used for searching for users, accessible via /index.php.…
- CVE-2020-123513 PoCsImproper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
- CVE-2020-123522 PoCsImproper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
- CVE-2020-124051 PoCWhen browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This…
- CVE-2020-124291 PoCOnline Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and authentication bypass…
- CVE-2020-124311 PoCA Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration…
- CVE-2020-124322 PoCsThe WOPI API integration for Vereign Collabora CODE through 4.2.2 does not properly restrict delivery of JavaScript to a victim's browser,…
- CVE-2020-124431 PoCBigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf…
- CVE-2020-124464 PoCsThe ene.sys driver in G.SKILL Trident Z Lighting Control through 1.00.08 exposes mapping and un-mapping of physical memory, reading and…
- CVE-2020-124471 PoCA Local File Inclusion (LFI) issue on Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users on the network to…
- CVE-2020-124581 PoCAn information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file…
- CVE-2020-124601 PoCOpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in…
- CVE-2020-124781 PoCTeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include backups or LDAP debug…
- CVE-2020-125003 PoCsPepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
- CVE-2020-125014 PoCsPepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
- CVE-2020-125023 PoCsPepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
- CVE-2020-125032 PoCsPepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
- CVE-2020-125044 PoCsPepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
- CVE-2020-125931 PoCSymantec Endpoint Detection & Response, prior to 4.5, may be susceptible to an information disclosure issue, which is a type of…
- CVE-2020-126071 PoCAn issue was discovered in fastecdsa before 2.1.2. When using the NIST P-256 curve in the ECDSA implementation, the point at infinity is…
- CVE-2020-126084 PoCsAn issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Monitoring Agent.…
- CVE-2020-126241 PoCThe League application before 2020-05-02 on Android sends a bearer token in an HTTP Authorization header to an arbitrary web site that…
- CVE-2020-126252 PoCsAn issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php…
- CVE-2020-126261 PoCAn issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was…
- CVE-2020-126292 PoCsinclude/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.
- CVE-2020-126381 PoCAn encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266_NONOS_SDK devices through 3.0.3, and…
- CVE-2020-126402 PoCsRoundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to…
- CVE-2020-126414 PoCsKEVrcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration…
- CVE-2020-126591 PoCAn issue was discovered in the Linux kernel before 5.6.7. xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write (by a user with…
- CVE-2020-126762 PoCsFusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a…
- CVE-2020-126951 PoCThe Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a…
- CVE-2020-126961 PoCThe iframe plugin before 4.5 for WordPress does not sanitize a URL.
- CVE-2020-127022 PoCsWeak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS application…
- CVE-2020-127041 PoCUliCMS before 2020.2 has PageController stored XSS.
- CVE-2020-127061 PoCMultiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the…
- CVE-2020-127071 PoCAn XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used…
- CVE-2020-127123 PoCsA vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 and 1.13 allows…
- CVE-2020-127132 PoCsAn issue was discovered in CipherMail Community Gateway and Professional/Enterprise Gateway 1.0.1 through 4.7.1-0 and CipherMail Webmail…
- CVE-2020-127142 PoCsAn issue was discovered in CipherMail Community Gateway Virtual Appliances and Professional/Enterprise Gateway Virtual Appliances versions…
- CVE-2020-127171 PoCThe COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere with COVID-19…
- CVE-2020-127202 PoCsvBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.
- CVE-2020-127401 PoCtcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the…
- CVE-2020-127532 PoCsAn issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Arbitrary code execution can occur via the…
- CVE-2020-127622 PoCsjson-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
- CVE-2020-127631 PoCTRENDnet ProView Wireless camera TV-IP512WN 1.0R 1.0.4 is vulnerable to an unauthenticated stack-based buffer overflow in handling RTSP…
- CVE-2020-127691 PoCAn issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to cause a panic via concurrent calls to…
- CVE-2020-127831 PoCExim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c…
- CVE-2020-127901 PoCIn the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does not properly sanitize the URL. This leads to Server-Side…
- CVE-2020-127982 PoCsCellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command prompt via the…
- CVE-2020-128005 PoCsThe drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code…
- CVE-2020-128251 PoClibcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption.
- CVE-2020-128262 PoCsA signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in…
- CVE-2020-128271 PoCMJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML document.
- CVE-2020-128321 PoCWordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the…
- CVE-2020-128353 PoCsAn issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe…
- CVE-2020-128371 PoCismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading images to garage doors. The magic bytes of PNG…
- CVE-2020-128381 PoCismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php.
- CVE-2020-128391 PoCismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkExpirationDate.php.
- CVE-2020-128401 PoCismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload sound files via /index.php
- CVE-2020-128411 PoCismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload imae files via /index.php
- CVE-2020-128421 PoCismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkUserExpirationDate.php.
- CVE-2020-128431 PoCismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading sounds to garage doors. The magic bytes for WAV…
- CVE-2020-128471 PoCPydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with an administrator…
- CVE-2020-128481 PoCIn Pydio Cells 2.0.4, once an authenticated user shares a file selecting the create a public link option, a hidden shared user account is…
- CVE-2020-128491 PoCPydio Cells 2.0.4 allows any user to upload a profile image to the web application, including standard and shared user roles. These…
- CVE-2020-128501 PoCThe following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio Cells Enterprise OVF…
- CVE-2020-128511 PoCPydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders…
- CVE-2020-128521 PoCThe update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to validate…
- CVE-2020-128531 PoCPydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially malicious HTML and…
- CVE-2020-128561 PoCOpenTrace, as used in COVIDSafe through v1.0.17, TraceTogether, ABTraceTogether, and other applications on iOS and Android, allows remote…
- CVE-2020-128611 PoCA heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to…
- CVE-2020-128621 PoCAn out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to…
- CVE-2020-128631 PoCAn out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to…
- CVE-2020-128641 PoCAn out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to…
- CVE-2020-128651 PoCA heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to…
- CVE-2020-128661 PoCA NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to…
- CVE-2020-128671 PoCA NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local…
- CVE-2020-128821 PoCSubmitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a Teaching Fellow.
- CVE-2020-129282 PoCsA vulnerability in a dynamically loaded AMD driver in AMD Ryzen Master V15 may allow any authenticated user to escalate privileges to NT…