CVE-2020-18000 to CVE-2020-18999
92 CVEs with public proof-of-concept exploits.
- CVE-2020-180201 PoCSQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone"…
- CVE-2020-180651 PoCCross Site Scripting (XSS) vulnerability exists in PopojiCMS 2.0.1 in admin.php?mod=menumanager--------- edit menu.
- CVE-2020-180771 PoCA buffer overflow vulnerability in the Virtual Path Mapping component of FTPShell v6.83 allows attackers to cause a denial of service (DoS).
- CVE-2020-180841 PoCCross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into the "referer" field…
- CVE-2020-181141 PoCAn arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM…
- CVE-2020-181161 PoCA lack of filtering for searched keywords in the search bar of YouDianCMS 8.0 allows attackers to perform SQL injection.
- CVE-2020-181211 PoCA configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell.
- CVE-2020-181231 PoCA cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily delete admin accounts.
- CVE-2020-181241 PoCA cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily reset account passwords.
- CVE-2020-181261 PoCMultiple stored cross-site scripting (XSS) vulnerabilities in the Sections module of Indexhibit 2.1.5 allows attackers to execute…
- CVE-2020-181271 PoCAn issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files.
- CVE-2020-181551 PoCSQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection.
- CVE-2020-181571 PoCCross Site Request Forgery (CSRF) vulnerability in MetInfo 6.1.3 via a doaddsave action in admin/index.php.
- CVE-2020-181581 PoCCross Site Scripting (XSS) vulnerability in HuCart 5.7.4 via nickname in index.php.
- CVE-2020-181751 PoCSQL Injection vulnerability in Metinfo 6.1.3 via a dosafety_emailadd action in basic.php.
- CVE-2020-181841 PoCIn PluxXml V5.7,the theme edit function /PluXml/core/admin/parametres_edittpl.php allows remote attackers to execute arbitrary PHP code by…
- CVE-2020-181851 PoCclass.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.
- CVE-2020-181951 PoCCross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via…
- CVE-2020-181981 PoCCross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the…
- CVE-2020-182152 PoCsMultiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parameters,…
- CVE-2020-182211 PoCCross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during…
- CVE-2020-182591 PoCED01-CMS v1.0 was discovered to contain a reflective cross-site scripting (XSS) vulnerability in the component sposts.php. This…
- CVE-2020-182611 PoCAn arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands.
- CVE-2020-182651 PoCCross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the…
- CVE-2020-182682 PoCsOpen Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the…
- CVE-2020-183241 PoCCross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.
- CVE-2020-183251 PoCMultilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.
- CVE-2020-183261 PoCCross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which…
- CVE-2020-183271 PoCCross Site Scripting (XSS) vulnerability exists in Alfresco Alfresco Community Edition v5.2.0 via the action parameter in the…
- CVE-2020-183781 PoCA NULL pointer dereference was discovered in SExpressionWasmBuilder::makeBlock in wasm/wasm-s-parser.c in Binaryen 1.38.26. A crafted wasm…
- CVE-2020-183821 PoCHeap-buffer-overflow in /src/wasm/wasm-binary.cpp in wasm::WasmBinaryBuilder::visitBlock(wasm::Block*) in Binaryen 1.38.26. A crafted wasm…
- CVE-2020-183951 PoCA NULL-pointer deference issue was discovered in GNU_gama::set() in ellipsoid.h in Gama 2.04 which can lead to a denial of service (DOS)…
- CVE-2020-184041 PoCAn issue was discovered in espcms version P8.18101601. There is a cross site scripting (XSS) vulnerability that allows arbitrary code to…
- CVE-2020-184091 PoCCross Site Request Forgery (CSRF) vulnerability was discovered in CatfishCMS 4.8.63 that would allow attackers to obtain administrator…
- CVE-2020-184101 PoCA stored cross site scripting (XSS) vulnerability in /index.php?admin-master-article-edit of Chaoji CMS v2.18 that allows attackers to…
- CVE-2020-184131 PoCStored cross site scripting (XSS) vulnerability in /index.php?admin-master-navmenu-add of Chaoji CMS v2.18 that allows attackers to…
- CVE-2020-184141 PoCStored cross site scripting (XSS) vulnerability in Chaoji CMS v2.18 that allows attackers to execute arbitrary code via…
- CVE-2020-184161 PoCAn cross site request forgery (CSRF) vulnerability discovered in Jymusic v2.0.0.,that allows attackers to execute arbitrary code via…
- CVE-2020-184181 PoCA Cross site request forgery (CSRF) vulnerability was discovered in FeiFeiCMS v4.1.190209, which allows attackers to create administrator…
- CVE-2020-184421 PoCInfinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_read" in the…
- CVE-2020-184541 PoCCross Site Request Forgery (CSRF) vulnerability in bycms v1.3 via admin.php/systems/index/module_id/70/group_id/1.html.
- CVE-2020-184571 PoCCross Site Request Forgery (CSRF) vulnerability exists in bycms v1.3.0 that can add an admin account via admin.php/ucenter/add.html.
- CVE-2020-184581 PoCCross Site Request Forgery (CSRF) vulnerability exists in DamiCMS v6.0.6 that can add an admin account via admin.php?s=/Admin/doadd.
- CVE-2020-184631 PoCCross Site Request Forgery (CSRF) vulnerability exists in v2.0.0 in video_list.php, which can let a malicious user delete a video message.
- CVE-2020-184641 PoCCross Site Request Forgery (CSRF) vulnerability in AikCms 2.0.0 in video_list.php, which can let a malicious user delete movie information.
- CVE-2020-184671 PoCCross Site Scripting (XSS) vulnerabilty exists in BigTree-CMS 4.4.3 in the tag name field found in the Tags page under the General menu…
- CVE-2020-185682 PoCsThe D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause remote command…
- CVE-2020-186481 PoCCross Site Request Forgery (CSRF) in JuQingCMS v1.0 allows remote attackers to gain local privileges via the component…
- CVE-2020-186511 PoCBuffer Overflow vulnerability in function ID3_Support::ID3v2Frame::getFrameValue in exempi 2.5.0 and earlier allows remote attackers to…
- CVE-2020-186521 PoCBuffer Overflow vulnerability in WEBP_Support.cpp in exempi 2.5.0 and earlier allows remote attackers to cause a denial of service via…
- CVE-2020-186541 PoCCross Site Scripting (XSS) in Wuzhi CMS v4.1.0 allows remote attackers to execute arbitrary code via the "Title" parameter in the…
- CVE-2020-186621 PoCSQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.
- CVE-2020-186851 PoCFloodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of unchecked prerequisites…
- CVE-2020-186941 PoCCross Site Request Forgery (CSRF) in IgnitedCMS v1.0 allows remote attackers to obtain sensitive information and gain privilege via the…
- CVE-2020-187131 PoCSQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in customerAction.php
- CVE-2020-187141 PoCSQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordModel.php's getdata…
- CVE-2020-187161 PoCSQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAction.php.
- CVE-2020-187171 PoCSQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in…
- CVE-2020-187232 PoCsStored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email…
- CVE-2020-187242 PoCsAuthenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an…
- CVE-2020-187341 PoCA stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
- CVE-2020-187351 PoCA heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
- CVE-2020-187372 PoCsAn issue was discovered in Typora 0.9.67. There is an XSS vulnerability that causes Remote Code Execution.
- CVE-2020-187461 PoCSQL Injection in AiteCMS v1.0 allows remote attackers to execute arbitrary code via the component "aitecms/login/diy_list.php".
- CVE-2020-187531 PoCAn issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to gain access to the system and escalate privileges via a…
- CVE-2020-187541 PoCAn information disclosure vulnerability exists within Dut Computer Control Engineering Co.'s PLC MAC1100.
- CVE-2020-187561 PoCAn arbitrary memory access vulnerability in the EPA protocol of Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to…
- CVE-2020-187571 PoCAn issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to cause persistent denial of service (DOS) via a crafted…
- CVE-2020-187581 PoCAn issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code.
- CVE-2020-187591 PoCAn information disclosure vulnerability exists in the EPA protocol of Dut Computer Control Engineering Co.'s PLC MAC1100.
- CVE-2020-187661 PoCA cross-site scripting (XSS) vulnerability AntSword v2.0.7 can remotely execute system commands.
- CVE-2020-187701 PoCAn issue was discovered in function zzip_disk_entry_to_file_header in mmapped.c in zziplib 0.13.69, which will lead to a denial-of-service.
- CVE-2020-187711 PoCExiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an…
- CVE-2020-187731 PoCAn invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a…
- CVE-2020-187741 PoCA float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS)…
- CVE-2020-187751 PoCIn Libav 12.3, there is a heap-based buffer over-read in vc1_decode_b_mb_intfi in vc1_block.c that allows an attacker to cause…
- CVE-2020-187761 PoCIn Libav 12.3, there is a segmentation fault in vc1_decode_b_mb_intfr in vc1_block.c that allows an attacker to cause denial-of-service…
- CVE-2020-187781 PoCIn Libav 12.3, there is a heap-based buffer over-read in vc1_decode_p_mb_intfi in vc1_block.c that allows an attacker to cause…
- CVE-2020-187811 PoCHeap buffer overflow vulnerability in FilePOSIX::read in File.cpp in audiofile 0.3.6 may cause denial-of-service via a crafted wav file,…
- CVE-2020-188311 PoCBuffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of…
- CVE-2020-188391 PoCBuffer Overflow vulnerability in HtmlOutputDev::page in poppler 0.75.0 allows attackers to cause a denial of service.
- CVE-2020-188781 PoCDirectory Traversal in Skycaiji v1.3 allows remote attackers to obtain sensitive information via the component…
- CVE-2020-188891 PoCCross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /admin/settings.php.
- CVE-2020-188971 PoCAn use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff before 20180623 allows attackers to cause a…
- CVE-2020-188981 PoCA stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a…
- CVE-2020-188991 PoCAn uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of…
- CVE-2020-189001 PoCA heap-based buffer overflow in the libexe_io_handle_read_coff_optional_header function of libyal libexe before 20181128. NOTE: the vendor…
- CVE-2020-189641 PoCCross Site Request Forgery (CSRF) Vulnerability in ForestBlog latest version via the website Management background, which could let a…
- CVE-2020-189711 PoCStack-based Buffer Overflow in PoDoFo v0.9.6 allows attackers to cause a denial of service via the component…
- CVE-2020-189721 PoCExposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via…
- CVE-2020-189741 PoCBuffer Overflow in Netwide Assembler (NASM) v2.15.xx allows attackers to cause a denial of service via 'crc64i' in the component…
- CVE-2020-189761 PoCBuffer Overflow in Tcpreplay v4.3.2 allows attackers to cause a Denial of Service via the 'do_checksum' function in 'checksum.c'. It can…