CVE-2020-15000 to CVE-2020-15999
138 CVEs with public proof-of-concept exploits.
- CVE-2020-150023 PoCsOX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API.
- CVE-2020-150031 PoCOX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string of a different user…
- CVE-2020-150042 PoCsOX App Suite through 7.10.3 allows stats/diagnostic?param= XSS.
- CVE-2020-150141 PoCpramodmahato BlogCMS through 2019-12-31 has admin/changepass.php CSRF.
- CVE-2020-150231 PoCAskey AP5100W devices through AP5100W_Dual_SIG_1.01.097 are affected by WPS PIN offline brute-force cracking. This arises because of…
- CVE-2020-150383 PoCsThe SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.
- CVE-2020-150463 PoCsThe web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a…
- CVE-2020-150503 PoCsAn issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary files from the…
- CVE-2020-150512 PoCsAn issue was discovered in Artica Proxy before 4.30.000000. Stored XSS exists via the Server Domain Name, Your Email Address, Group Name,…
- CVE-2020-150521 PoCAn issue was discovered in Artica Proxy CE before 4.28.030.418. SQL Injection exists via the Netmask, Hostname, and Alias fields.
- CVE-2020-150532 PoCsAn issue was discovered in Artica Proxy CE before 4.28.030.418. Reflected XSS exists via these search fields: real time request, System…
- CVE-2020-150811 PoCInformation exposure in the upload directory in PrestaShop
- CVE-2020-150921 PoCStored XSS in TimelineJS3
- CVE-2020-150951 PoCSensitive information exposure through logs in npm cli
- CVE-2020-151111 PoCCRLF vulnerability in Fiber
- CVE-2020-151191 PoCDOM-based XSS in auth0-lock
- CVE-2020-151231 PoCCommand injection in codecov (npm package)
- CVE-2020-151291 PoCOpen redirect in Traefik
- CVE-2020-151352 PoCsCSRF vulnerability in save-server
- CVE-2020-151381 PoCCross-Site Scripting in Prism
- CVE-2020-151483 PoCsUnsafe deserialization in Yii 2
- CVE-2020-151491 PoCAccount takeover in NodeBB
- CVE-2020-151521 PoCServer-Side Request Forgery in ftp-srv
- CVE-2020-151561 PoCXSS due to lack of CSRF validation for replying/publishing
- CVE-2020-151601 PoCBlind SQL Injection in PrestaShop
- CVE-2020-151691 PoCXSS in Action View
- CVE-2020-151751 PoCUnauthenticated File Deletion in GLPI
- CVE-2020-151821 PoCCross-site Request Forgery leading to RCE in SOY CMS
- CVE-2020-151881 PoCUnauthenticated Remote Code Execution in SOY CMS
- CVE-2020-151891 PoCRemote Code Execution in SOY CMS
- CVE-2020-152151 PoCContext isolation bypass in Electron
- CVE-2020-152251 PoCDenial of Service vulnerability in django-filter
- CVE-2020-152261 PoCSQL Injection in GLPI Search API
- CVE-2020-152274 PoCsRemote Code Execution vulnerability
- CVE-2020-152281 PoCEnvironment Variable Injection in GitHub Actions
- CVE-2020-152383 PoCsLocal privilege escalation Blueman
- CVE-2020-152531 PoCStored XSS in Grocy
- CVE-2020-152552 PoCsCSV injection in Anuko Time Tracker
- CVE-2020-152561 PoCPrototype pollution in object-path
- CVE-2020-152573 PoCscontainerd-shim API Exposed to Host Network Containers
- CVE-2020-152613 PoCsUnquoted service path vulnerability on Veyon
- CVE-2020-153001 PoCSuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document.
- CVE-2020-153021 PoCIn Argent RecoveryManager before 0xdc350d09f71c48c5D22fBE2741e4d6A03970E192, the executeRecovery function does not require any signatures…
- CVE-2020-153081 PoCSupport Incident Tracker (aka SiT! or SiTracker) 3.67 p2 allows post-authentication SQL injection via the site_edit.php typeid or site…
- CVE-2020-153572 PoCsNetwork Analysis functionality in Askey AP5100W_Dual_SIG_1.01.097 and all prior versions allows remote attackers to execute arbitrary…
- CVE-2020-153581 PoCIn SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse…
- CVE-2020-153601 PoCcom.docker.vmnetd in Docker Desktop 2.3.0.3 allows privilege escalation because of a lack of client verification.
- CVE-2020-153633 PoCsThe Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.
- CVE-2020-153643 PoCsThe Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.
- CVE-2020-153651 PoCLibRaw before 0.20-Beta3 has an out-of-bounds write in parse_exif() in metadata\exif_gps.cpp via an unrecognized AtomName and a zero value…
- CVE-2020-153671 PoCVenki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability…
- CVE-2020-153681 PoCAsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering a triple fault via…
- CVE-2020-153901 PoCpyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via…
- CVE-2020-153921 PoCA user enumeration vulnerability flaw was found in Venki Supravizio BPM 10.1.2. This issue occurs during password recovery, where a…
- CVE-2020-153942 PoCsThe REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request,…
- CVE-2020-153951 PoCIn MediaInfoLib in MediaArea MediaInfo 20.03, there is a stack-based buffer over-read in Streams_Fill_PerStream in…
- CVE-2020-153961 PoCIn HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race,…
- CVE-2020-153971 PoCHylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileged users (e.g.,…
- CVE-2020-154011 PoCIOBit Malware Fighter Pro 8.0.2.547 allows local users to gain privileges for file deletion by manipulating malicious flagged file…
- CVE-2020-154151 PoCKEVOn DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution…
- CVE-2020-154161 PoCThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58…
- CVE-2020-154361 PoCUse-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of…
- CVE-2020-154681 PoCPersian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter.
- CVE-2020-154782 PoCsThe Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors.
- CVE-2020-154871 PoCRe:Desk 2.3 contains a blind unauthenticated SQL injection vulnerability in the getBaseCriteria() function in the…
- CVE-2020-154881 PoCRe:Desk 2.3 allows insecure file upload.
- CVE-2020-154924 PoCsAn issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application…
- CVE-2020-155003 PoCsAn issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an…
- CVE-2020-155054 PoCsKEVA remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2,…
- CVE-2020-155301 PoCAn issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain NT AUTHORITY\SYSTEM privileges because…
- CVE-2020-155312 PoCsSilicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air remote code execution…
- CVE-2020-155321 PoCSilicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air denial of service…
- CVE-2020-155351 PoCAn issue was discovered in the bestsoftinc Car Rental System plugin through 1.3 for WordPress. Persistent XSS can occur via any of the…
- CVE-2020-155361 PoCAn issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can occur via any of…
- CVE-2020-155372 PoCsAn issue was discovered in the Vanguard plugin 2.1 for WordPress. XSS can occur via the mails/new title field, a product field to the p/…
- CVE-2020-155382 PoCsXSS can occur in We-com Municipality portal CMS 2.1.x via the cerca/ search bar.
- CVE-2020-155392 PoCsSQL injection can occur in We-com Municipality portal CMS 2.1.x via the cerca/ keywords field.
- CVE-2020-155402 PoCsWe-com OpenData CMS 2.0 allows SQL Injection via the username field on the administrator login page.
- CVE-2020-155685 PoCsTerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method…
- CVE-2020-155702 PoCsThe parse_report() function in whoopsie.c in Whoopsie through 0.2.69 mishandles memory allocation failures, which allows an attacker to…
- CVE-2020-155881 PoCAn issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an…
- CVE-2020-155891 PoCA design issue was discovered in GetInternetRequestHandle, InternetSendRequestEx and InternetSendRequestByBitrate in the client side of…
- CVE-2020-155981 PoCTrustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Trustwave has…
- CVE-2020-155991 PoCVictor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.
- CVE-2020-156003 PoCsAn issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.
- CVE-2020-156431 PoCThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64.…
- CVE-2020-156451 PoCThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64.…
- CVE-2020-156851 PoCDuring the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted…
- CVE-2020-156881 PoCThe HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an…
- CVE-2020-156902 PoCsIn Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character.
- CVE-2020-156921 PoCIn Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument can be a local file…
- CVE-2020-156931 PoCIn Nim 1.2.4, the standard library httpClient is vulnerable to a CR-LF injection in the target URL. An injection is possible if the…
- CVE-2020-156941 PoCIn Nim 1.2.4, the standard library httpClient fails to properly validate the server response. For example,…
- CVE-2020-157161 PoCRosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php script. A remote…
- CVE-2020-157182 PoCsRosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote…
- CVE-2020-157783 PoCsscp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the…
- CVE-2020-157801 PoCAn issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs…
- CVE-2020-158061 PoCCODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
- CVE-2020-158071 PoCGNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files.
- CVE-2020-158431 PoCActFax Version 7.10 Build 0335 (2020-05-25) is susceptible to a privilege escalation vulnerability due to insecure folder permissions on…
- CVE-2020-158491 PoCRe:Desk 2.3 has a blind authenticated SQL injection vulnerability in the SettingsController class, in the actionEmailTemplates() method. A…
- CVE-2020-158501 PoCInsecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access the Nakivo Director…
- CVE-2020-158511 PoCLack of access control in Nakivo Backup & Replication Transporter version 9.4.0.r43656 allows remote users to access unencrypted backup…
- CVE-2020-158601 PoCParallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an authenticated user…
- CVE-2020-158661 PoCmruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrect VM stack…
- CVE-2020-158674 PoCsThe git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if…
- CVE-2020-158732 PoCsIn LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to…
- CVE-2020-158771 PoCAn issue was discovered in LibreNMS before 1.65.1. It has insufficient access control for normal users because of "'guard' => 'admin'"…
- CVE-2020-158884 PoCsLua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow,…
- CVE-2020-158891 PoCLua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list…
- CVE-2020-158901 PoCLuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.
- CVE-2020-158932 PoCsAn issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port…
- CVE-2020-158952 PoCsAn XSS issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. In the file webinc/js/info.php, no output filtration is…
- CVE-2020-159064 PoCstiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
- CVE-2020-159121 PoCTesla Model 3 vehicles allow attackers to open a door by leveraging access to a legitimate key card, and then using NFC Relay. NOTE: the…
- CVE-2020-159162 PoCsgoform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via…
- CVE-2020-159181 PoCMultiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0.
- CVE-2020-159191 PoCA Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0.
- CVE-2020-159206 PoCsThere is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with…
- CVE-2020-159213 PoCsMida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted…
- CVE-2020-159223 PoCsThere is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with…
- CVE-2020-159231 PoCMida eFramework through 2.9.0 allows unauthenticated ../ directory traversal.
- CVE-2020-159241 PoCThere is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is required. The…
- CVE-2020-159281 PoCIn Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters to test-browser/index.cfm allow directory traversal.
- CVE-2020-159291 PoCIn Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to…
- CVE-2020-159302 PoCsAn XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
- CVE-2020-159311 PoCNetwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the…
- CVE-2020-159433 PoCsAn issue was discovered in the Gantt-Chart module before 5.5.4 for Jira. Due to a missing privilege check, it is possible to read and…
- CVE-2020-159443 PoCsAn issue was discovered in the Gantt-Chart module before 5.5.5 for Jira. Due to missing validation of user input, it is vulnerable to a…
- CVE-2020-159451 PoCLua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) because it…
- CVE-2020-159481 PoCeGain Chat 15.5.5 allows XSS via the Name (aka full_name) field.
- CVE-2020-159491 PoCImmuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover.
- CVE-2020-159501 PoCImmuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.
- CVE-2020-159511 PoCImmuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject arbitrary HTML…
- CVE-2020-159521 PoCImmuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permissions.…
- CVE-2020-159563 PoCsActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer overflow and…
- CVE-2020-159582 PoCsAn issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote…
- CVE-2020-159994 PoCsKEVHeap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption…