CVE-2020-13000 to CVE-2020-13999
249 CVEs with public proof-of-concept exploits.
- CVE-2020-130942 PoCsDolibarr before 11.0.4 allows XSS.
- CVE-2020-131091 PoCMorita Shogi 64 through 2020-05-02 for Nintendo 64 devices allows remote attackers to execute arbitrary code via crafted packet data to…
- CVE-2020-131101 PoCThe kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs…
- CVE-2020-131172 PoCsWavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key…
- CVE-2020-131183 PoCsAn issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the…
- CVE-2020-131191 PoCismartgate PRO 1.5.9 is vulnerable to clickjacking.
- CVE-2020-131211 PoCSubmitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.
- CVE-2020-131251 PoCAn issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in…
- CVE-2020-131311 PoCAn issue was discovered in Yubico libykpiv before 2.1.0. lib/util.c in this library (which is included in yubico-piv-tool) does not…
- CVE-2020-131321 PoCAn issue was discovered in Yubico libykpiv before 2.1.0. An attacker can trigger an incorrect free() in the ykpiv_util_generate_key()…
- CVE-2020-131442 PoCsStudio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New…
- CVE-2020-131491 PoCWeak permissions on the "%PROGRAMDATA%\MSI\Dragon Center" folder in Dragon Center before 2.6.2003.2401, shipped with Micro-Star MSI Gaming…
- CVE-2020-131517 PoCsAerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua,…
- CVE-2020-131522 PoCsA remote user can create a specially crafted M3U file, media playlist file that when loaded by the target user, will trigger a memory…
- CVE-2020-131551 PoCclearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the…
- CVE-2020-131561 PoCmodules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI.
- CVE-2020-131571 PoCmodules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=edit&userid= URI.…
- CVE-2020-131582 PoCsArtica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter.
- CVE-2020-131591 PoCArtica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac,…
- CVE-2020-131605 PoCsAnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.
- CVE-2020-131622 PoCsA time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for…
- CVE-2020-131663 PoCsThe management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for…
- CVE-2020-131672 PoCsNetsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers)…
- CVE-2020-131681 PoCSysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter.
- CVE-2020-132241 PoCTP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.1 build 200401,…
- CVE-2020-132252 PoCsphpIPAM 1.4 contains a stored cross site scripting (XSS) vulnerability within the Edit User Instructions field of the User Instructions…
- CVE-2020-132271 PoCAn issue was discovered in Sysax Multi Server 6.90. An attacker can determine the username (under which the web server is running) by…
- CVE-2020-132282 PoCsAn issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter.
- CVE-2020-132291 PoCAn issue was discovered in Sysax Multi Server 6.90. A session can be hijacked if one observes the sid value in any /scgi URI, because it…
- CVE-2020-132451 PoCCertain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10,…
- CVE-2020-132462 PoCsAn issue was discovered in Gitea through 1.11.5. An attacker can trigger a deadlock by initiating a transfer of a repository's ownership…
- CVE-2020-132471 PoCBooleBox Secure File Sharing Utility before 4.2.3.0 allows CSV injection via a crafted user name that is mishandled during export from the…
- CVE-2020-132481 PoCBooleBox Secure File Sharing Utility before 4.2.3.0 allows stored XSS via a crafted avatar field within My Account JSON data to…
- CVE-2020-132521 PoCCentreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in…
- CVE-2020-132541 PoCAn issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key…
- CVE-2020-132582 PoCsContentful through 2020-05-21 for Python allows reflected XSS, as demonstrated by the api parameter to the-example-app.py.
- CVE-2020-132593 PoCsA vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote…
- CVE-2020-132603 PoCsA vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated attacker to upload…
- CVE-2020-132772 PoCsAn authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5
- CVE-2020-132781 PoCReflected Cross-Site Scripting vulnerability in Modules.php in RosarioSIS Student Information System < 6.5.1 allows remote attackers to…
- CVE-2020-133241 PoCA vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed…
- CVE-2020-133301 PoCAn issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS in import the Bitbucket…
- CVE-2020-133311 PoCAn issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the Wiki pasges.
- CVE-2020-133381 PoCAn issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability…
- CVE-2020-133431 PoCAn issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template
- CVE-2020-133761 PoCSecurEnvoy SecurMail 9.3.503 allows attackers to upload executable files and achieve OS command execution via a crafted SecurEnvoyReply…
- CVE-2020-133771 PoCThe web-services interface of Loadbalancer.org Enterprise VA MAX through 8.3.8 could allow an authenticated, remote, low-privileged…
- CVE-2020-133781 PoCLoadbalancer.org Enterprise VA MAX through 8.3.8 has an OS Command Injection vulnerability that allows a remote authenticated attacker to…
- CVE-2020-133795 PoCsThe avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any…
- CVE-2020-133812 PoCsopenSIS through 7.4 allows SQL Injection.
- CVE-2020-133823 PoCsopenSIS through 7.4 has Incorrect Access Control.
- CVE-2020-133833 PoCsopenSIS through 7.4 allows Directory Traversal.
- CVE-2020-133841 PoCMonstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because,…
- CVE-2020-133882 PoCsAn exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python. When loading…
- CVE-2020-133891 PoCAn issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0…
- CVE-2020-133902 PoCsAn issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0…
- CVE-2020-133912 PoCsAn issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0…
- CVE-2020-133922 PoCsAn issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0…
- CVE-2020-133933 PoCsAn issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0…
- CVE-2020-133942 PoCsAn issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0…
- CVE-2020-133981 PoCAn issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in…
- CVE-2020-134011 PoCAn issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6…
- CVE-2020-134052 PoCsuserfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users…
- CVE-2020-134151 PoCAn issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can…
- CVE-2020-134241 PoCThe XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure.
- CVE-2020-134265 PoCsThe Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it presents, allowing…
- CVE-2020-134271 PoCVictor CMS 1.0 has Persistent XSS in admin/users.php?source=add_user via the user_name, user_firstname, or user_lastname parameter.
- CVE-2020-134324 PoCsrejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an…
- CVE-2020-134341 PoCSQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
- CVE-2020-134351 PoCSQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c.
- CVE-2020-134381 PoCffjpeg through 2020-02-24 has an invalid read in jfif_encode in jfif.c.
- CVE-2020-134431 PoCExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose Msg, Add…
- CVE-2020-134482 PoCsQuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the…
- CVE-2020-134492 PoCsA directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.
- CVE-2020-134502 PoCsA directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any…
- CVE-2020-134512 PoCsAn incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice…
- CVE-2020-134521 PoCIn Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the…
- CVE-2020-134651 PoCThe security protection in Gigadevice GD32F103 devices allows physical attackers to redirect the control flow and execute arbitrary code…
- CVE-2020-134681 PoCGigadevice GD32F130 devices allow physical attackers to escalate their debug interface permissions via fault injection into inter-IC…
- CVE-2020-134691 PoCThe flash memory readout protection in Gigadevice GD32VF103 devices allows physical attackers to extract firmware via the debug interface…
- CVE-2020-134701 PoCGigadevice GD32F103 and GD32F130 devices allow physical attackers to extract data via the probing of easily accessible bonding wires and…
- CVE-2020-134711 PoCApex Microelectronics APM32F103 devices allow physical attackers to execute arbitrary code via a power glitch and a specific flash…
- CVE-2020-134721 PoCThe flash memory readout protection in Gigadevice GD32F103 devices allows physical attackers to extract firmware via the debug interface…
- CVE-2020-134732 PoCsNCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.
- CVE-2020-134742 PoCsIn NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged…
- CVE-2020-134761 PoCNCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module.
- CVE-2020-134803 PoCsVerint Workforce Optimization (WFO) 15.2 allows HTML injection via the "send email" feature.
- CVE-2020-134831 PoCThe Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the…
- CVE-2020-134871 PoCThe bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at…
- CVE-2020-134931 PoCA heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. A specially…
- CVE-2020-134941 PoCA heap overflow vulnerability exists in the Pixar OpenUSD 20.05 parsing of compressed string tokens in binary USD files. A specially…
- CVE-2020-134951 PoCAn exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles file offsets in binary USD files. A specially crafted malformed…
- CVE-2020-134961 PoCAn exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially crafted malformed…
- CVE-2020-134971 PoCAn exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially crafted malformed…
- CVE-2020-134981 PoCAn exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially crafted malformed…
- CVE-2020-134991 PoCAn SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.…
- CVE-2020-135001 PoCSQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.…
- CVE-2020-135011 PoCAn SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.…
- CVE-2020-135091 PoCAn information disclosure vulnerability exists in the WinRing0x64 Driver Privileged I/O Read IRPs functionality of NZXT CAM 4.8.0. A…
- CVE-2020-135101 PoCAn information disclosure vulnerability exists in the WinRing0x64 Driver Privileged I/O Read IRPs functionality of NZXT CAM 4.8.0. A…
- CVE-2020-135111 PoCAn information disclosure vulnerability exists in the WinRing0x64 Driver Privileged I/O Read IRPs functionality of NZXT CAM 4.8.0. A…
- CVE-2020-135121 PoCA privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A…
- CVE-2020-135131 PoCA privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A…
- CVE-2020-135141 PoCA privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A…
- CVE-2020-135151 PoCA privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c40a148 functionality of NZXT CAM 4.8.0. A specially crafted…
- CVE-2020-135161 PoCAn information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c406144 functionality of NZXT CAM 4.8.0. A specially…
- CVE-2020-135171 PoCAn information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c406104 functionality of NZXT CAM 4.8.0. A specially…
- CVE-2020-135181 PoCAn information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c402084 functionality of NZXT CAM 4.8.0. A specially…
- CVE-2020-135192 PoCsA privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c402088 functionality of NZXT CAM 4.8.0. A specially crafted…
- CVE-2020-135201 PoCAn out of bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 reconstructs paths from binary USD files. A…
- CVE-2020-135221 PoCAn exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request…
- CVE-2020-135231 PoCAn exploitable information disclosure vulnerability exists in SoftPerfect’s RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request…
- CVE-2020-135241 PoCAn out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD files. A specially…
- CVE-2020-135251 PoCThe sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL injection in…
- CVE-2020-135261 PoCSQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP request can cause…
- CVE-2020-135291 PoCAn exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server…
- CVE-2020-135301 PoCA denial-of-service vulnerability exists in the Ethernet/IP server functionality of the EIP Stack Group OpENer 2.3 and development commit…
- CVE-2020-135311 PoCA use-after-free vulnerability exists in a way Pixar OpenUSD 20.08 processes reference paths textual USD files. A specially crafted file…
- CVE-2020-135321 PoCA privilege escalation vulnerability exists in Dream Report 5 R20-2. In the default configuration, the Syncfusion Dashboard Service…
- CVE-2020-135331 PoCA privilege escalation vulnerability exists in Dream Report 5 R20-2. IIn the default configuration, the following registry keys, which…
- CVE-2020-135341 PoCA privilege escalation vulnerability exists in Dream Report 5 R20-2. COM Class Identifiers (CLSID), installed by Dream Report 5 20-2,…
- CVE-2020-135351 PoCA privilege escalation vulnerability exists in Kepware LinkMaster 3.0.94.0. In its default configuration, an attacker can globally…
- CVE-2020-135361 PoCAn exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation.…
- CVE-2020-135371 PoCAn exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation.…
- CVE-2020-135391 PoCAn exploitable local privilege elevation vulnerability exists in the file system permissions of the Win-911 Enterprise V4.20.13 install…
- CVE-2020-135401 PoCAn exploitable local privilege elevation vulnerability exists in the file system permissions of the Win-911 Enterprise V4.20.13 install…
- CVE-2020-135411 PoCAn exploitable local privilege elevation vulnerability exists in the file system permissions of the Mobile-911 Server V2.5 install…
- CVE-2020-135421 PoCA local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depending on the vector…
- CVE-2020-135431 PoCA code execution vulnerability exists in the WebSocket functionality of Webkit WebKitGTK 2.30.0. A specially crafted web page can trigger…
- CVE-2020-135441 PoCAn exploitable sign extension vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021’s TextMaker…
- CVE-2020-135451 PoCAn exploitable signed conversion vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021’s TextMaker…
- CVE-2020-135461 PoCIn SoftMaker Software GmbH SoftMaker Office TextMaker 2021 (revision 1014), a specially crafted document can cause the document parser to…
- CVE-2020-135471 PoCA type confusion vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially…
- CVE-2020-135481 PoCIn Foxit Reader 10.1.0.37527, a specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary…
- CVE-2020-135491 PoCAn exploitable local privilege elevation vulnerability exists in the file system permissions of Sytech XL Reporter v14.0.1 install…
- CVE-2020-135501 PoCA local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted…
- CVE-2020-135511 PoCAn exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1…
- CVE-2020-135521 PoCAn exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1…
- CVE-2020-135531 PoCAn exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1…
- CVE-2020-135541 PoCAn exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1…
- CVE-2020-135551 PoCAn exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1…
- CVE-2020-135561 PoCAn out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Group OpENer 2.3 and development commit…
- CVE-2020-135571 PoCA use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially…
- CVE-2020-135581 PoCA code execution vulnerability exists in the AudioSourceProviderGStreamer functionality of Webkit WebKitGTK 2.30.1. A specially crafted…
- CVE-2020-135591 PoCA denial-of-service vulnerability exists in the traffic-logging functionality of FreyrSCADA IEC-60879-5-104 Server Simulator 21.04.028. A…
- CVE-2020-135601 PoCA use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially…
- CVE-2020-135611 PoCAn out-of-bounds write vulnerability exists in the TIFF parser of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to…
- CVE-2020-135621 PoCA cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to…
- CVE-2020-135631 PoCA cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to…
- CVE-2020-135641 PoCA cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to…
- CVE-2020-135651 PoCAn open redirect vulnerability exists in the return_page redirection functionality of phpGACL 3.3.7, OpenEMR 5.0.2 and OpenEMR development…
- CVE-2020-135661 PoCSQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send…
- CVE-2020-135671 PoCMultiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker…
- CVE-2020-135681 PoCSQL injection vulnerability exists in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an…
- CVE-2020-135691 PoCA cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit…
- CVE-2020-135701 PoCA use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.0.37527. A specially crafted…
- CVE-2020-135711 PoCAn out-of-bounds write vulnerability exists in the SGI RLE decompression functionality of Accusoft ImageGear 19.8. A specially crafted…
- CVE-2020-135721 PoCA heap overflow vulnerability exists in the way the GIF parser decodes LZW compressed streams in Accusoft ImageGear 19.8. A specially…
- CVE-2020-135731 PoCA denial-of-service vulnerability exists in the Ethernet/IP server functionality of Rockwell Automation RSLinx Classic 2.57.00.14 CPR 9 SR…
- CVE-2020-135741 PoCA denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP…
- CVE-2020-135751 PoCA denial-of-service vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP…
- CVE-2020-135761 PoCA code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request…
- CVE-2020-135771 PoCA denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP…
- CVE-2020-135781 PoCA denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP…
- CVE-2020-135791 PoCAn exploitable integer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker…
- CVE-2020-135801 PoCAn exploitable heap-based buffer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s…
- CVE-2020-135811 PoCIn SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014), a specially crafted document can cause the document parser to…
- CVE-2020-135821 PoCA denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can…
- CVE-2020-135831 PoCA denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can…
- CVE-2020-135841 PoCAn exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specially crafted HTML web page can cause a…
- CVE-2020-135851 PoCAn out-of-bounds write vulnerability exists in the PSD Header processing functionality of Accusoft ImageGear 19.8. A specially crafted…
- CVE-2020-135861 PoCA memory corruption vulnerability exists in the Excel Document SST Record 0x00fc functionality of SoftMaker Software GmbH SoftMaker Office…
- CVE-2020-135871 PoCAn exploitable SQL injection vulnerability exists in the "forms_fields_rules/rules" page of the Rukovoditel Project Management App 2.7.2.…
- CVE-2020-135881 PoCAn exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The…
- CVE-2020-135891 PoCAn exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The…
- CVE-2020-135901 PoCMultiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page of the Rukovoditel Project Management App 2.7.2. A…
- CVE-2020-135911 PoCAn exploitable SQL injection vulnerability exists in the "access_rules/rules_form" page of the Rukovoditel Project Management App 2.7.2. A…
- CVE-2020-135921 PoCAn exploitable SQL injection vulnerability exists in "global_lists/choices" page of the Rukovoditel Project Management App 2.7.2. A…
- CVE-2020-136201 PoCFastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading to an attacker's…
- CVE-2020-136231 PoCJerryScript 2.2.0 allows attackers to cause a denial of service (stack consumption) via a proxy operation.
- CVE-2020-136381 PoClib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue…
- CVE-2020-136403 PoCsA SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL…
- CVE-2020-136421 PoCAn issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do…
- CVE-2020-136431 PoCAn issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce…
- CVE-2020-136541 PoCXWiki Platform before 12.8 mishandles escaping in the property displayer.
- CVE-2020-136561 PoCIn Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds…
- CVE-2020-136581 PoCIn Lansweeper 8.0.130.17, the web console is vulnerable to a CSRF attack that would allow a low-level Lansweeper user to elevate their…
- CVE-2020-136601 PoCCMS Made Simple through 2.2.14 allows XSS via a crafted File Picker profile name.
- CVE-2020-136712 PoCsKEVDrupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect…
- CVE-2020-136932 PoCsAn unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.
- CVE-2020-136992 PoCsTeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer…
- CVE-2020-137001 PoCAn issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via…
- CVE-2020-137562 PoCsSabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function…
- CVE-2020-137571 PoCPython-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact,…
- CVE-2020-137581 PoCmodules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.0.950 allows XSS…
- CVE-2020-137681 PoCIn MiniShare before 1.4.2, there is a stack-based buffer overflow via an HTTP PUT request, which allows an attacker to achieve arbitrary…
- CVE-2020-137772 PoCsGnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an…
- CVE-2020-137882 PoCsHarbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible…
- CVE-2020-138022 PoCsRebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification.
- CVE-2020-138201 PoCExtreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.
- CVE-2020-138221 PoCThe Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer…
- CVE-2020-138251 PoCA cross-site scripting (XSS) vulnerability in i-doit 1.14.2 allows remote attackers to inject arbitrary web script or HTML via the…
- CVE-2020-138261 PoCA CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands…
- CVE-2020-138271 PoCphpList before 3.5.4 allows XSS via /lists/admin/user.php and /lists/admin/users.php.
- CVE-2020-138501 PoCArtica Pandora FMS 7.44 has inadequate access controls on a web folder.
- CVE-2020-138514 PoCsArtica Pandora FMS 7.44 allows remote command execution via the events feature.
- CVE-2020-138521 PoCArtica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature.
- CVE-2020-138531 PoCArtica Pandora FMS 7.44 has persistent XSS in the Messages feature.
- CVE-2020-138541 PoCArtica Pandora FMS 7.44 allows privilege escalation.
- CVE-2020-138551 PoCArtica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Repository Manager feature.
- CVE-2020-138641 PoCThe Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that…
- CVE-2020-138651 PoCThe Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create…
- CVE-2020-138661 PoCWinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges by replacing an…
- CVE-2020-138712 PoCsSQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.
- CVE-2020-138721 PoCRoyal TS before 5 has a 0.0.0.0 listener, which makes it easier for attackers to bypass tunnel authentication via a brute-force approach.
- CVE-2020-138841 PoCCitrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain…
- CVE-2020-138851 PoCCitrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation…
- CVE-2020-138865 PoCsIntelbras TIP 200 60.61.75.15, TIP 200 LITE 60.61.75.15, and TIP 300 65.61.75.22 devices allow cgi-bin/cgiServer.exx?page=../ Directory…
- CVE-2020-138891 PoCshowAlert() in the administration panel in Bludit 3.12.0 allows XSS.
- CVE-2020-138901 PoCThe Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard.
- CVE-2020-138982 PoCsAn issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_process in sdp.c has a NULL pointer…
- CVE-2020-138993 PoCsAn issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_process_incoming_request in janus.c discloses…
- CVE-2020-139003 PoCsAn issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_preparse in sdp.c has a NULL pointer…
- CVE-2020-139013 PoCsAn issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_merge in sdp.c has a stack-based buffer…
- CVE-2020-139041 PoCFFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees…
- CVE-2020-139111 PoCYour Online Shop 1.8.0 allows authenticated users to trigger XSS via a Change Name or Change Surname operation.
- CVE-2020-139211 PoC**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.
- CVE-2020-139221 PoCApache DolphinScheduler (incubating) Permission vulnerability
- CVE-2020-139251 PoCSimilar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the…
- CVE-2020-139275 PoCsKEVThe previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security…
- CVE-2020-139333 PoCsApache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.
- CVE-2020-139354 PoCsThe payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to…
- CVE-2020-139361 PoCVelocity Sandbox Bypass
- CVE-2020-139377 PoCsApache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6,…
- CVE-2020-139411 PoCReported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler…
- CVE-2020-1394213 PoCsRemote Code Execution in Apache Unomi
- CVE-2020-139457 PoCsIn Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is…
- CVE-2020-139511 PoCAttackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.
- CVE-2020-139551 PoCHttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients vulnerable to…
- CVE-2020-139572 PoCsApache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used…
- CVE-2020-139581 PoCA vulnerability in Apache OpenOffice scripting events allows an attacker to construct documents containing hyperlinks pointing to an…
- CVE-2020-139653 PoCsKEVAn issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because…
- CVE-2020-139731 PoCOWASP json-sanitizer before 1.2.1 allows XSS. An attacker who controls a substring of the input JSON, and controls another substring…
- CVE-2020-139761 PoCAn issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary commands via shell…
- CVE-2020-139921 PoCAn issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A Stored XSS issue allows remote unauthenticated attackers to abuse a…
- CVE-2020-139931 PoCAn issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A blind time-based SQL injection issue allows remote unauthenticated…
- CVE-2020-139941 PoCAn issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A privileged user can achieve code execution on the server via a ticket…
- CVE-2020-139952 PoCsU.S. Air Force Sensor Data Management System extract75 has a buffer overflow that leads to code execution. An overflow in a global…
- CVE-2020-139961 PoCThe J2Store plugin before 3.3.13 for Joomla! allows a SQL injection attack by a trusted store manager.