CVE-2020-19000 to CVE-2020-19999
146 CVEs with public proof-of-concept exploits.
- CVE-2020-191071 PoCSQL Injection vulnerability in Online Book Store v1.0 via the isbn parameter to edit_book.php, which could let a remote malicious user…
- CVE-2020-191081 PoCSQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remote malicious user…
- CVE-2020-191091 PoCSQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_edit.php, which could let a remote malicious…
- CVE-2020-191121 PoCSQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_delete.php, which could let a remote malicious…
- CVE-2020-191131 PoCArbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution.
- CVE-2020-191141 PoCSQL Injection vulnerability in Online Book Store v1.0 via the publisher parameter to edit_book.php, which could let a remote malicious…
- CVE-2020-191181 PoCCross Site Scripting (XSS) vulnerabiity in YzmCMS 5.2 via the site_code parameter in admin/index/init.html.
- CVE-2020-191312 PoCsBuffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component…
- CVE-2020-191461 PoCImproper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath'…
- CVE-2020-191471 PoCImproper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()'…
- CVE-2020-191481 PoCCross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter…
- CVE-2020-191501 PoCImproper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of…
- CVE-2020-191511 PoCCommand Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML…
- CVE-2020-191541 PoCImproper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the…
- CVE-2020-191551 PoCImproper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary…
- CVE-2020-191561 PoCCross Site Scripting (XSS) in Ari Adminer v1 allows remote attackers to execute arbitrary code via the 'Title' parameter of the 'Add New…
- CVE-2020-191651 PoCPHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.
- CVE-2020-191851 PoCBuffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a…
- CVE-2020-191861 PoCBuffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial…
- CVE-2020-191871 PoCBuffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of…
- CVE-2020-191881 PoCBuffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of…
- CVE-2020-191891 PoCBuffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause…
- CVE-2020-191901 PoCBuffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of…
- CVE-2020-191991 PoCA Cross Site Request Forgery (CSRF) vulnerability exists in PHPOK 5.2.060 via admin.php?c=admin&f=save, which could let a remote malicious…
- CVE-2020-192481 PoCSQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to…
- CVE-2020-192631 PoCA cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily escalate user privileges to administrator via…
- CVE-2020-192641 PoCA cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily add users via index.php?s=/user/ApiAdminUser/itemAdd.
- CVE-2020-192651 PoCA stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Basis/links component of Dswjcms 1.6.4 allows attackers to…
- CVE-2020-192661 PoCA stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Site/articleList component of Dswjcms 1.6.4 allows attackers to…
- CVE-2020-192802 PoCsJeesns 1.4.2 contains a cross-site request forgery (CSRF) which allows attackers to escalate privileges and perform sensitive program…
- CVE-2020-192811 PoCA stored cross-site scripting (XSS) vulnerability in the /manage/loginusername component of Jeesns 1.4.2 allows attackers to execute…
- CVE-2020-192822 PoCsA reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2020-192832 PoCsA reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to execute arbitrary…
- CVE-2020-192841 PoCA stored cross-site scripting (XSS) vulnerability in the /group/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary…
- CVE-2020-192851 PoCA stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to execute arbitrary web…
- CVE-2020-192861 PoCA stored cross-site scripting (XSS) vulnerability in the /question/detail component of Jeesns 1.4.2 allows attackers to execute arbitrary…
- CVE-2020-192871 PoCA stored cross-site scripting (XSS) vulnerability in the /group/post component of Jeesns 1.4.2 allows attackers to execute arbitrary web…
- CVE-2020-192881 PoCA stored cross-site scripting (XSS) vulnerability in the /localhost/u component of Jeesns 1.4.2 allows attackers to execute arbitrary web…
- CVE-2020-192891 PoCA stored cross-site scripting (XSS) vulnerability in the /member/picture/album component of Jeesns 1.4.2 allows attackers to execute…
- CVE-2020-192901 PoCA stored cross-site scripting (XSS) vulnerability in the /weibo/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary…
- CVE-2020-192911 PoCA stored cross-site scripting (XSS) vulnerability in the /weibo/publishdata component of Jeesns 1.4.2 allows attackers to execute…
- CVE-2020-192921 PoCA stored cross-site scripting (XSS) vulnerability in the /question/ask component of Jeesns 1.4.2 allows attackers to execute arbitrary web…
- CVE-2020-192931 PoCA stored cross-site scripting (XSS) vulnerability in the /article/add component of Jeesns 1.4.2 allows attackers to execute arbitrary web…
- CVE-2020-192941 PoCA stored cross-site scripting (XSS) vulnerability in the /article/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary…
- CVE-2020-192952 PoCsA reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to execute arbitrary…
- CVE-2020-193011 PoCA vulnerability in the vae_admin_rule database table of vaeThink v1.0.1 allows attackers to execute arbitrary code via a crafted payload…
- CVE-2020-193021 PoCAn arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a webshell via changing…
- CVE-2020-193051 PoCAn issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the column is…
- CVE-2020-193161 PoCOS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.
- CVE-2020-193191 PoCBuffer overflow vulnerability in DLINK 619L version B 2.06beta via the FILECODE parameter on login.
- CVE-2020-193201 PoCBuffer overflow vulnerability in DLINK 619L version B 2.06beta via the curTime parameter on login.
- CVE-2020-193231 PoCAn issue was discovered in /bin/mini_upnpd on D-Link DIR-619L 2.06beta devices. There is a heap buffer overflow allowing remote attackers…
- CVE-2020-193604 PoCsLocal file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a file, which can lead…
- CVE-2020-193611 PoCReflected XSS in Medintux v2.16.000 CCAM.php by manipulating the mot1 parameter can result in an attacker performing malicious actions to…
- CVE-2020-193621 PoCReflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious…
- CVE-2020-193632 PoCsVtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.
- CVE-2020-193641 PoCOpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.
- CVE-2020-194171 PoCEmerson Smart Wireless Gateway 1420 4.6.59 allows non-privileged users (such as the default account 'maint') to perform administrative…
- CVE-2020-194191 PoCIncorrect Access Control in Emerson Smart Wireless Gateway 1420 4.6.59 allows remote attackers to obtain sensitive device information from…
- CVE-2020-194631 PoCAn issue has been found in function vfprintf in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow.
- CVE-2020-194641 PoCAn issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack…
- CVE-2020-194651 PoCAn issue has been found in function ObjectStream::getObject in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an…
- CVE-2020-194661 PoCAn issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due…
- CVE-2020-194671 PoCAn issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due…
- CVE-2020-194681 PoCAn issue has been found in function EmbedStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a null…
- CVE-2020-194691 PoCAn issue has been found in function DCTStream::reset in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid…
- CVE-2020-194701 PoCAn issue has been found in function DCTStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a NULL…
- CVE-2020-194711 PoCAn issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an…
- CVE-2020-194721 PoCAn issue has been found in function DCTStream::readHuffSym in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an…
- CVE-2020-194731 PoCAn issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an…
- CVE-2020-194741 PoCAn issue has been found in function Gfx::doShowText in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an Use…
- CVE-2020-194751 PoCAn issue has been found in function CCITTFaxStream::lookChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an…
- CVE-2020-194811 PoCAn issue was discovered in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid memory read in gf_m2ts_process_pmt in…
- CVE-2020-194881 PoCAn issue was discovered in box_code_apple.c:119 in Gpac MP4Box 0.8.0, allows attackers to cause a Denial of Service due to an invalid read…
- CVE-2020-194901 PoCtinyexr 0.9.5 has a integer overflow over-write in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.
- CVE-2020-194911 PoCThere is an invalid memory access bug in cgif.c that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial…
- CVE-2020-194921 PoCThere is a floating point exception in ReadImage that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial…
- CVE-2020-194971 PoCInteger overflow vulnerability in Mat_VarReadNextInfo5 in mat5.c in tbeu matio (aka MAT File I/O Library) 1.5.17, allows attackers to…
- CVE-2020-194981 PoCFloating point exception in function Fraction in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other…
- CVE-2020-194991 PoCAn issue was discovered in heif::Box_iref::get_references in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly…
- CVE-2020-195131 PoCBuffer overflow in FinalWire Ltd AIDA64 Engineer 6.00.5100 allows attackers to execute arbitrary code by creating a crafted input that…
- CVE-2020-195151 PoCqdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.
- CVE-2020-195591 PoCAn issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a remote attacker to execute arbitrary code via a crafted payload to the…
- CVE-2020-195861 PoCIncorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4…
- CVE-2020-195871 PoCCross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote attackers to run…
- CVE-2020-195951 PoCBuffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.
- CVE-2020-195961 PoCBuffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username.
- CVE-2020-196131 PoCServer Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version 20190503.
- CVE-2020-196161 PoCCross Site Scripting (XSS) vulnerability in mblog 3.5 via the post header field to /post/editing.
- CVE-2020-196171 PoCCross Site Scripting (XSS) vulnerability in mblog 3.5 via the nickname field to /settings/profile.
- CVE-2020-196181 PoCCross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing.
- CVE-2020-196191 PoCCross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile.
- CVE-2020-196251 PoCRemote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute…
- CVE-2020-196261 PoCCross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via…
- CVE-2020-196401 PoCAn issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. An unauthenticated attacker can reboot the device…
- CVE-2020-196411 PoCAn issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. Authenticated attackers with the "Operator" Privilege…
- CVE-2020-196421 PoCAn issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. A local attacker can execute arbitrary code via…
- CVE-2020-196431 PoCCross Site Scripting (XSS) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B via all fields in the FTP settings…
- CVE-2020-196643 PoCsDrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.
- CVE-2020-196671 PoCStack-based buffer overflow and unconditional jump in ReadXPMImage in coders/xpm.c in ImageMagick 7.0.10-7.
- CVE-2020-196681 PoCUnverified indexs into the array lead to out of bound access in the gif_out_code function in fromgif.c in libsixel 1.8.6.
- CVE-2020-196691 PoCCross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via…
- CVE-2020-196701 PoCIn Niushop B2B2C Multi-Business Basic Edition V1.11, authentication can be bypassed, causing administrators to reset any passwords.
- CVE-2020-196721 PoCNiushop B2B2C Multi-business basic version V1.11, can bypass the administrator to obtain the background upload interface, through…
- CVE-2020-196781 PoCDirectory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain…
- CVE-2020-196821 PoCA Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.
- CVE-2020-196831 PoCA Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php.
- CVE-2020-196921 PoCBuffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in…
- CVE-2020-196931 PoCAn issue found in Espruino Espruino 6ea4c0a allows an attacker to execute arbitrrary code via oldFunc parameter of the…
- CVE-2020-196951 PoCBuffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the…
- CVE-2020-196981 PoCCross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted…
- CVE-2020-197171 PoCAn unhandled memory allocation failure in Core/Ap48bdlAtom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, leading to a denial…
- CVE-2020-197181 PoCAn unhandled memory allocation failure in Core/Ap4Atom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, leading to a denial of…
- CVE-2020-197192 PoCsA buffer overflow vulnerability in Ap4ElstAtom.cpp of Bento 1.5.1-628 leads to a denial of service (DOS).
- CVE-2020-197201 PoCAn unhandled memory allocation failure in Core/AP4IkmsAtom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, leading to a denial…
- CVE-2020-197211 PoCA heap buffer overflow vulnerability in Ap4TrunAtom.cpp of Bento 1.5.1-628 may lead to an out-of-bounds write while running mp42aac,…
- CVE-2020-197221 PoCAn unhandled memory allocation failure in Core/Ap4Atom.cpp of Bento 1.5.1-628 causes a direct copy to NULL pointer dereference, leading to…
- CVE-2020-197241 PoCA memory consumption issue in get_data function in binutils/nm.c in GNU nm before 2.34 allows attackers to cause a denial of service via…
- CVE-2020-197251 PoCThere is a use-after-free vulnerability in file pdd_simplifier.cpp in Z3 before 4.8.8. It occurs when the solver attempt to simplify the…
- CVE-2020-197262 PoCsAn issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory…
- CVE-2020-197521 PoCThe find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference.
- CVE-2020-197621 PoCAutomated Logic Corporation (ALC) WebCTRL System 6.5 and prior allows remote attackers to execute any JavaScript code via a XSS payload…
- CVE-2020-198771 PoCDBHcms v1.2.0 has a directory traversal vulnerability as there is no directory control function in directory /dbhcms/. A remote…
- CVE-2020-198781 PoCDBHcms v1.2.0 has a sensitive information leaks vulnerability as there is no security access control in /dbhcms/ext/news/ext.news.be.php,…
- CVE-2020-198791 PoCDBHcms v1.2.0 has a stored xss vulnerability as there is no security filter of $_GET['dbhcms_pid'] variable in dbhcms\page.php line 107,
- CVE-2020-198801 PoCDBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function form 'Name' in dbhcms\types.php, A remote…
- CVE-2020-198811 PoCDBHcms v1.2.0 has a reflected xss vulnerability as there is no security filter in dbhcms\mod\mod.selector.php line 108 for…
- CVE-2020-198821 PoCDBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for 'menu_description' variable in…
- CVE-2020-198831 PoCDBHcms v1.2.0 has a stored xss vulnerability as there is no security filter in dbhcms\mod\mod.users.view.php line 57 for user_login, A…
- CVE-2020-198841 PoCDBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcms\mod\mod.domain.edit.php line 119.
- CVE-2020-198851 PoCDBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name']' variable in…
- CVE-2020-198861 PoCDBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can delete any menu.
- CVE-2020-198871 PoCDBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_description']'…
- CVE-2020-198881 PoCDBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.php for empty cache…
- CVE-2020-198891 PoCDBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.
- CVE-2020-198901 PoCDBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is no filter…
- CVE-2020-198911 PoCDBHcms v1.2.0 has an Arbitrary file write vulnerability in dbhcms\mod\mod.editor.php $_POST['updatefile'] is filename and…
- CVE-2020-198971 PoCA reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl…
- CVE-2020-199021 PoCDirectory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the…
- CVE-2020-199141 PoCCross Site Scripting (XSS) in xiunobbs 4.0.4 allows remote attackers to execute arbitrary web script or HTML via the attachment upload…
- CVE-2020-199152 PoCsCross Site Scripting (XSS vulnerability exists in WUZHI CMS 4.1.0 via the mailbox username in index.php.
- CVE-2020-199491 PoCA cross-site scripting (XSS) vulnerability in the /link/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web…
- CVE-2020-199501 PoCA cross-site scripting (XSS) vulnerability in the /banner/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web…
- CVE-2020-199511 PoCA cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive components of the…
- CVE-2020-199621 PoCA stored cross-site scripting (XSS) vulnerability in the getClientIp function in /lib/tinwin.class.php of Chaoji CMS 2.39, allows…
- CVE-2020-199641 PoCA Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator…