CVE-2020-20000 to CVE-2020-20999
103 CVEs with public proof-of-concept exploits.
- CVE-2020-200211 PoCAn issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH…
- CVE-2020-200671 PoCFile upload vulnerability in ebCMS v.1.1.0 allows a remote attacker to execute arbitrary code via the upload type parameter.
- CVE-2020-200701 PoCCross Site Scripting vulnerability found in wkeyuan DWSurvey 1.0 allows a remote attacker to execute arbitrary code via thequltemld…
- CVE-2020-200932 PoCsThe Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly represent URI…
- CVE-2020-200942 PoCsInstagram iOS 106.0 and prior and Android 107.0.0.11 and prior user interface does not properly represent URI messages to the user, which…
- CVE-2020-200952 PoCsiMessage (Messages app) iOS 12.4 and prior user interface does not properly represent URI messages to the user, which results in URI…
- CVE-2020-200962 PoCsWhatsapp iOS 2.19.80 and prior and Android 2.19.222 and prior user interface does not properly represent URI messages to the user, which…
- CVE-2020-201241 PoCWuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php.
- CVE-2020-201361 PoCQuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration…
- CVE-2020-201381 PoCCross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4.
- CVE-2020-201392 PoCsCross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.
- CVE-2020-201402 PoCsCross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17.
- CVE-2020-201412 PoCsCross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.
- CVE-2020-201422 PoCsCross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table & Charts 2.7.17.
- CVE-2020-201841 PoCGateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.
- CVE-2020-202111 PoCMikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console process. An…
- CVE-2020-202121 PoCMikrotik RouterOs 6.44.5 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/console process. An…
- CVE-2020-202142 PoCsMikrotik RouterOs 6.44.6 (long-term tree) suffers from an assertion failure vulnerability in the btest process. An authenticated remote…
- CVE-2020-202181 PoCMikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute process. An…
- CVE-2020-202191 PoCMikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/igmp-proxy process. An…
- CVE-2020-202202 PoCsMikrotik RouterOs prior to stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/bfd process. An authenticated…
- CVE-2020-202211 PoCMikrotik RouterOs before 6.44.6 (long-term tree) suffers from an uncontrolled resource consumption vulnerability in the /nova/bin/cerm…
- CVE-2020-202222 PoCsMikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An…
- CVE-2020-202272 PoCsMikrotik RouterOs stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenticated remote…
- CVE-2020-202301 PoCMikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the sshd process. An authenticated remote…
- CVE-2020-202311 PoCMikrotik RouterOs through stable version 6.48.3 suffers from a memory corruption vulnerability in the /nova/bin/detnet process. An…
- CVE-2020-202362 PoCsMikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated…
- CVE-2020-202372 PoCsMikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated…
- CVE-2020-202452 PoCsMikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the log process. An authenticated remote attacker can…
- CVE-2020-202462 PoCsMikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the mactel process. An authenticated remote attacker can…
- CVE-2020-202481 PoCMikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the memtest process. An authenticated remote…
- CVE-2020-202491 PoCMikrotik RouterOs before stable 6.47 suffers from a memory corruption vulnerability in the resolver process. By sending a crafted packet,…
- CVE-2020-202501 PoCMikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An…
- CVE-2020-202521 PoCMikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An…
- CVE-2020-202531 PoCMikrotik RouterOs before 6.47 (stable tree) suffers from a divison by zero vulnerability in the /nova/bin/lcdstat process. An…
- CVE-2020-202541 PoCMikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An…
- CVE-2020-202621 PoCMikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /ram/pckg/security/nova/bin/ipsec…
- CVE-2020-202641 PoCMikrotik RouterOs before 6.47 (stable tree) in the /ram/pckg/advanced-tools/nova/bin/netwatch process. An authenticated remote attacker…
- CVE-2020-202652 PoCsMikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /ram/pckg/wireless/nova/bin/wireless…
- CVE-2020-202661 PoCMikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/dot1x process. An…
- CVE-2020-202671 PoCMikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/resolver process. An…
- CVE-2020-202772 PoCsThere are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server versions 2.7 to 2.10…
- CVE-2020-202852 PoCsThere is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via user/login.php
- CVE-2020-203001 PoCSQL injection vulnerability in the wp_where function in WeiPHP 5.0.
- CVE-2020-203351 PoCBuffer Overflow vulnerability in Antirez Kilo before commit 7709a04ae8520c5b04d261616098cebf742f5a23 allows a remote attacker to cause a…
- CVE-2020-203401 PoCA SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sensitive database…
- CVE-2020-203431 PoCWTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that allows…
- CVE-2020-203441 PoCWTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the background articles…
- CVE-2020-203451 PoCWTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to…
- CVE-2020-203471 PoCWTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module.
- CVE-2020-203481 PoCWTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management module.
- CVE-2020-203491 PoCWTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module.
- CVE-2020-204121 PoClib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a…
- CVE-2020-204441 PoCJact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET…
- CVE-2020-204511 PoCDenial of Service issue in FFmpeg 4.2 due to resource management errors via fftools/cmdutils.c.
- CVE-2020-205021 PoCCross Site Request Forgery found in yzCMS v.2.0 allows a remote attacker to execute arbitrary code via the token check function.
- CVE-2020-205141 PoCA Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all…
- CVE-2020-205211 PoCCross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the comment parameter.
- CVE-2020-205221 PoCCross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the registering user…
- CVE-2020-205821 PoCA server side request forgery (SSRF) vulnerability in /ApiAdminDomainSettings.php of MipCMS 5.0.1 allows attackers to access sensitive…
- CVE-2020-205831 PoCA SQL injection vulnerability in /question.php of LJCMS Version v4.3.R60321 allows attackers to obtain sensitive database information.
- CVE-2020-205841 PoCA cross site scripting vulnerability in baigo CMS v4.0-beta-1 allows attackers to execute arbitrary web scripts or HTML via the form…
- CVE-2020-205851 PoCA blind SQL injection in /admin/?n=logs&c=index&a=dode of Metinfo 7.0 beta allows attackers to access sensitive database information.
- CVE-2020-205861 PoCA cross site request forgery (CSRF) vulnerability in the /xyhai.php?s=/Auth/editUser URI of XYHCMS V3.6 allows attackers to edit any…
- CVE-2020-205891 PoCCross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html…
- CVE-2020-205931 PoCA cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrator account.
- CVE-2020-205951 PoCA cross-site request forgery (CSRF) in OPMS v1.3 and below allows attackers to arbitrarily add a user account via /user/add.
- CVE-2020-205971 PoCA cross-site scripting (XSS) vulnerability in the potrtalItemName parameter in \web\PortalController.java of lemon V1.10.0 allows…
- CVE-2020-205981 PoCA cross-site scripting (XSS) vulnerability in the Editing component of lemon V1.10.0 allows attackers to execute arbitrary web scripts or…
- CVE-2020-206001 PoCMetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index&a=doAddColumn.
- CVE-2020-206011 PoCAn issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.
- CVE-2020-206271 PoCThe includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings…
- CVE-2020-206401 PoCCross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity…
- CVE-2020-206421 PoCCross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via…
- CVE-2020-206701 PoCAn arbitrary file upload vulnerability in /admin/media/upload of ZKEACMS V3.2.0 allows attackers to execute arbitrary code via a crafted…
- CVE-2020-206711 PoCA cross-site request forgery (CSRF) in KiteCMS V1.1 allows attackers to arbitrarily add an administrator account.
- CVE-2020-206721 PoCAn arbitrary file upload vulnerability in /admin/upload/uploadfile of KiteCMS V1.1 allows attackers to getshell via a crafted PHP file.
- CVE-2020-206931 PoCA Cross-Site Request Forgery (CSRF) in GilaCMS v1.11.4 allows authenticated attackers to arbitrarily add administrator accounts.
- CVE-2020-206951 PoCA stored cross-site scripting (XSS) vulnerability in GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2020-206981 PoCA remote code execution (RCE) vulnerability in /1.com.php of S-CMS PHP v3.0 allows attackers to getshell via modification of a PHP file.
- CVE-2020-207031 PoCBuffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.
- CVE-2020-207261 PoCCross Site Request Forgery vulnerability in Gila GilaCMS v.1.11.4 allows a remote attacker to execute arbitrary code via the…
- CVE-2020-207401 PoCPDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version().
- CVE-2020-207971 PoCFlameCMS 3.3.5 contains a time-based blind SQL injection vulnerability in /account/register.php.
- CVE-2020-207991 PoCJeeCMS 1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML…
- CVE-2020-208081 PoCCross Site Scripting vulnerability in Qibosoft qibosoft v.7 and before allows a remote attacker to execute arbitrary code via the eindtijd…
- CVE-2020-208911 PoCBuffer Overflow vulnerability in function config_input in libavfilter/vf_gblur.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of…
- CVE-2020-208921 PoCAn issue was discovered in function filter_frame in libavfilter/vf_lenscorrection.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of…
- CVE-2020-208961 PoCAn issue was discovered in function latm_write_packet in libavformat/latmenc.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of…
- CVE-2020-208981 PoCInteger Overflow vulnerability in function filter16_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a…
- CVE-2020-209071 PoCMetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in…
- CVE-2020-209081 PoCAkaunting v1.3.17 was discovered to contain a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary…
- CVE-2020-209431 PoCA Cross-Site Request Forgery (CSRF) in /member/post.php?job=postnew&step=post of Qibosoft v7 allows attackers to force victim users into…
- CVE-2020-209441 PoCAn issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files.
- CVE-2020-209451 PoCA Cross-Site Request Forgery (CSRF) in /admin/index.php?lfj=member&action=editmember of Qibosoft v7 allows attackers to arbitrarily add…
- CVE-2020-209461 PoCQibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&action=add.
- CVE-2020-209691 PoCFile Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.
- CVE-2020-209711 PoCCross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index.
- CVE-2020-209751 PoCIn \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter.
- CVE-2020-209821 PoCCross Site Scripting (XSS) vulnerability in shadoweb wdja v1.5.1, allows attackers to execute arbitrary code and gain escalated…
- CVE-2020-209882 PoCsA cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attackers to execute…
- CVE-2020-209891 PoCA cross-site request forgery (CSRF) in /admin/maintenance/ of Domainmod 4.13 allows attackers to arbitrarily delete logs.
- CVE-2020-209901 PoCA cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to execute arbitrary web…