CVE-2020-21000 to CVE-2020-21999
140 CVEs with public proof-of-concept exploits.
- CVE-2020-210122 PoCsSourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to…
- CVE-2020-210131 PoCemlog v6.0.0 contains a SQL injection via /admin/comment.php.
- CVE-2020-210141 PoCemlog v6.0.0 contains an arbitrary file deletion vulnerability in admin/plugin.php.
- CVE-2020-210161 PoCD-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via…
- CVE-2020-210481 PoCAn issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file.
- CVE-2020-210491 PoCAn invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted…
- CVE-2020-210501 PoCLibsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at fromgif.c.
- CVE-2020-210581 PoCCross Site Scripting vulnerability in Typora v.0.9.79 allows a remote attacker to execute arbitrary code via the mermaid sytax.
- CVE-2020-210601 PoCSQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the…
- CVE-2020-210661 PoCAn issue was discovered in Bento4 v1.5.1.0. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a…
- CVE-2020-211201 PoCSQL Injection vulnerability in file home\controls\cart.class.php in UQCMS 2.1.3, allows attackers execute arbitrary commands via the…
- CVE-2020-211261 PoCMetInfo 7.0.0 contains a Cross-Site Request Forgery (CSRF) via admin/?n=admin&c=index&a=doSaveInfo.
- CVE-2020-211301 PoCCross Site Scripting (XSS) vulnerability in HisiPHP 2.0.8 via the group name in addgroup.html.
- CVE-2020-211391 PoCEC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add…
- CVE-2020-211411 PoCiCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add.
- CVE-2020-211421 PoCCross Site Scripting (XSS) vulnerabilty in IPFire 2.23 via the IPfire web UI in the mail.cgi.
- CVE-2020-211461 PoCFeehi CMS 2.0.8 is affected by a cross-site scripting (XSS) vulnerability. When the user name is inserted as JavaScript code, browsing the…
- CVE-2020-211472 PoCsRockOA V1.9.8 is affected by a cross-site scripting (XSS) vulnerability which allows remote attackers to send malicious code to the…
- CVE-2020-211611 PoCCross Site Scripting (XSS) vulnerability in Ruckus Wireless ZoneDirector 9.8.3.0.
- CVE-2020-211791 PoCSql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to…
- CVE-2020-211801 PoCSql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to…
- CVE-2020-212245 PoCsA Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a malicious login packet to…
- CVE-2020-212281 PoCJIZHICMS 1.5.1 contains a cross-site scripting (XSS) vulnerability in the component /user/release.html, which allows attackers to…
- CVE-2020-212361 PoCA vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user…
- CVE-2020-212461 PoCCross Site Scripting vulnerability in YiiCMS v.1.0 allows a remote attacker to execute arbitrary code via the news function.
- CVE-2020-212681 PoCCross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment…
- CVE-2020-213251 PoCAn issue in WUZHI CMS v.4.1.0 allows a remote attacker to execute arbitrary code via the set_chache method of the function\common.func.php…
- CVE-2020-213561 PoCAn information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host when 'name = "file"…
- CVE-2020-213571 PoCA stored cross site scripting (XSS) vulnerability in /admin.php?mod=user&act=addnew of PopojiCMS 1.2 allows attackers to execute arbitrary…
- CVE-2020-213651 PoCDirectory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive…
- CVE-2020-213661 PoCCross Site Request Forgery vulnerability in GreenCMS v.2.3 allows an attacker to gain privileges via the adduser function of index.php.
- CVE-2020-213781 PoCSQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.
- CVE-2020-214001 PoCSQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the…
- CVE-2020-214801 PoCAn arbitrary file write vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted PHP file.
- CVE-2020-214811 PoCAn arbitrary file upload vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted .txt file which is later…
- CVE-2020-214821 PoCA cross-site scripting (XSS) vulnerability in RGCMS v1.06 allows attackers to obtain the administrator's cookie via a crafted payload in…
- CVE-2020-214831 PoCAn arbitrary file upload vulnerability in Jizhicms v1.5 allows attackers to execute arbitrary code via a crafted .jpg file which is later…
- CVE-2020-214851 PoCCross Site Scripting vulnerability in Alluxio v.1.8.1 allows a remote attacker to executea arbitrary code via the path parameter in the…
- CVE-2020-214931 PoCAn issue in the component route\user.php of Xiuno BBS v4.0.4 allows attackers to enumerate usernames.
- CVE-2020-214941 PoCA cross-site scripting (XSS) vulnerability in the component install\install.sql of Xiuno BBS 4.0.4 allows attackers to execute arbitrary…
- CVE-2020-214951 PoCA cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute…
- CVE-2020-214961 PoCA cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute…
- CVE-2020-215031 PoCwaimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet…
- CVE-2020-215171 PoCCross Site Scripting (XSS) vulnerability in MetInfo 7.0.0 via the gourl parameter in login.php.
- CVE-2020-215291 PoCfig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c.
- CVE-2020-215301 PoCfig2dev 3.2.7b contains a segmentation fault in the read_objects function in read.c.
- CVE-2020-215311 PoCfig2dev 3.2.7b contains a global buffer overflow in the conv_pattern_index function in gencgm.c.
- CVE-2020-215321 PoCfig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c.
- CVE-2020-215331 PoCfig2dev 3.2.7b contains a stack buffer overflow in the read_textobject function in read.c.
- CVE-2020-215341 PoCfig2dev 3.2.7b contains a global buffer overflow in the get_line function in read.c.
- CVE-2020-215351 PoCfig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c.
- CVE-2020-215471 PoCLibsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c.
- CVE-2020-215481 PoCLibsixel 1.8.3 contains a heap-based buffer overflow in the sixel_encode_highcolor function in tosixel.c.
- CVE-2020-215641 PoCAn issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote command…
- CVE-2020-215831 PoCAn issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path…
- CVE-2020-215852 PoCsVulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module.
- CVE-2020-215941 PoClibde265 v1.0.4 contains a heap buffer overflow in the put_epel_hv_fallback function, which can be exploited via a crafted a file.
- CVE-2020-215951 PoClibde265 v1.0.4 contains a heap buffer overflow in the mc_luma function, which can be exploited via a crafted a file.
- CVE-2020-215961 PoClibde265 v1.0.4 contains a global buffer overflow in the decode_CABAC_bit function, which can be exploited via a crafted a file.
- CVE-2020-215971 PoClibde265 v1.0.4 contains a heap buffer overflow in the mc_chroma function, which can be exploited via a crafted a file.
- CVE-2020-215981 PoClibde265 v1.0.4 contains a heap buffer overflow in the ff_hevc_put_unweighted_pred_8_sse function, which can be exploited via a crafted a…
- CVE-2020-215991 PoClibde265 v1.0.4 contains a heap buffer overflow in the de265_image::available_zscan function, which can be exploited via a crafted a file.
- CVE-2020-216001 PoClibde265 v1.0.4 contains a heap buffer overflow in the put_weighted_pred_avg_16_fallback function, which can be exploited via a crafted a…
- CVE-2020-216011 PoClibde265 v1.0.4 contains a stack buffer overflow in the put_qpel_fallback function, which can be exploited via a crafted a file.
- CVE-2020-216021 PoClibde265 v1.0.4 contains a heap buffer overflow in the put_weighted_bipred_16_fallback function, which can be exploited via a crafted a…
- CVE-2020-216031 PoClibde265 v1.0.4 contains a heap buffer overflow in the put_qpel_0_0_fallback_16 function, which can be exploited via a crafted a file.
- CVE-2020-216041 PoClibde265 v1.0.4 contains a heap buffer overflow fault in the _mm_loadl_epi64 function, which can be exploited via a crafted a file.
- CVE-2020-216051 PoClibde265 v1.0.4 contains a segmentation fault in the apply_sao_internal function, which can be exploited via a crafted a file.
- CVE-2020-216061 PoClibde265 v1.0.4 contains a heap buffer overflow fault in the put_epel_16_fallback function, which can be exploited via a crafted a file.
- CVE-2020-216431 PoCCross Site Scripting (XSS) vulnerability in HongCMS 3.0 allows attackers to run arbitrary code via the callback parameter to /ajax/myshop.
- CVE-2020-216581 PoCA Cross-Site Request Forgery (CSRF) in WDJA CMS v1.5.2 allows attackers to arbitrarily add administrator accounts via a crafted URL.
- CVE-2020-216671 PoCIn fastadmin-tp6 v1.0, in the file app/admin/controller/Ajax.php the 'table' parameter passed is not filtered so a malicious parameter can…
- CVE-2020-216751 PoCA stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of service…
- CVE-2020-216761 PoCA stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of…
- CVE-2020-216771 PoCA heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4 allows attackers to cause a…
- CVE-2020-216781 PoCA global buffer overflow in the genmp_writefontmacro_latex component in genmp.c of fig2dev 3.2.7b allows attackers to cause a denial of…
- CVE-2020-216791 PoCBuffer Overflow vulnerability in WritePCXImage function in pcx.c in GraphicsMagick 1.4 allows remote attackers to cause a denial of…
- CVE-2020-216801 PoCA stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service…
- CVE-2020-216811 PoCA global buffer overflow in the set_color component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via…
- CVE-2020-216821 PoCA global buffer overflow in the set_fill component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via…
- CVE-2020-216831 PoCA global buffer overflow in the shade_or_tint_name_after_declare_color in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a…
- CVE-2020-216841 PoCA global buffer overflow in the put_font in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via…
- CVE-2020-216881 PoCA heap-use-after-free in the av_freep function in libavutil/mem.c of FFmpeg 4.2 allows attackers to execute arbitrary code.
- CVE-2020-216971 PoCA heap-use-after-free in the mpeg_mux_write_packet function in libavformat/mpegenc.c of FFmpeg 4.2 allows to cause a denial of service…
- CVE-2020-217101 PoCA divide by zero issue discovered in eps_print_page in gdevepsn.c in Artifex Software GhostScript 9.50 allows remote attackers to cause a…
- CVE-2020-217241 PoCBuffer Overflow vulnerability in ExtractorInformation function in streamExtractor.cpp in oggvideotools 0.9.1 allows remaote attackers to…
- CVE-2020-218061 PoCSQL Injection Vulnerability in ECTouch v2 via the shop page in index.php..
- CVE-2020-218081 PoCSQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics.php.
- CVE-2020-218092 PoCsSQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and the (2) group_price…
- CVE-2020-218131 PoCA heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114.
- CVE-2020-218141 PoCA heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlwescape ../../programs/escape.c:97.
- CVE-2020-218151 PoCA null pointer deference issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114, which causes a denial of…
- CVE-2020-218161 PoCA heab based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:46.
- CVE-2020-218171 PoCA null pointer dereference issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:29. which causes a denial of…
- CVE-2020-218181 PoCA heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:48.
- CVE-2020-218191 PoCA heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641via htmlescape ../../programs/escape.c:51.
- CVE-2020-218271 PoCA heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2379.
- CVE-2020-218301 PoCA heap based buffer overflow vulneraibility exists in GNU LibreDWG 0.10 via bit_calc_CRC ../../src/bits.c:2213.
- CVE-2020-218311 PoCA heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_handles ../../src/decode.c:2637.
- CVE-2020-218321 PoCA heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2417.
- CVE-2020-218331 PoCA heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_classes ../../src/decode.c:2440.
- CVE-2020-218341 PoCA null pointer deference issue exists in GNU LibreDWG 0.10 via get_bmp ../../programs/dwgbmp.c:164.
- CVE-2020-218351 PoCA null pointer deference issue exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2337.
- CVE-2020-218361 PoCA heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_preview ../../src/decode.c:3175.
- CVE-2020-218381 PoCA heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_appinfo ../../src/decode.c:2842.
- CVE-2020-218391 PoCAn issue was discovered in GNU LibreDWG 0.10. Crafted input will lead to an memory leak in dwg_decode_eed ../../src/decode.c:3638.
- CVE-2020-218401 PoCA heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_search_sentinel ../../src/bits.c:1985.
- CVE-2020-218411 PoCA heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_B ../../src/bits.c:135.
- CVE-2020-218421 PoCA heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_revhistory ../../src/decode.c:3051.
- CVE-2020-218431 PoCA heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_RC ../../src/bits.c:318.
- CVE-2020-218441 PoCGNU LibreDWG 0.10 is affected by: memcpy-param-overlap. The impact is: execute arbitrary code (remote). The component is:…
- CVE-2020-218451 PoCCodoforum 4.8.3 allows HTML Injection in the 'admin dashboard Manage users Section.'
- CVE-2020-218811 PoCCross Site Request Forgery (CSRF) vulnerability in admin.php in DuxCMS 2.1 allows remote attackers to modtify application data via…
- CVE-2020-218831 PoCUnibox U-50 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a OS command injection vulnerability in /tools/ping,…
- CVE-2020-218841 PoCUnibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF) vulnerability in…
- CVE-2020-218901 PoCBuffer Overflow vulnerability in clj_media_size function in devices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attackers to cause…
- CVE-2020-218961 PoCA Use After Free vulnerability in svg_dev_text_span_as_paths_defs function in source/fitz/svg-device.c in Artifex Software MuPDF 1.16.0…
- CVE-2020-219131 PoCInternational Components for Unicode (ICU-20850) v66.1 was discovered to contain a use after free bug in the pkg_createWithAssemblyCode…
- CVE-2020-219291 PoCA stored cross site scripting (XSS) vulnerability in the web_copyright field of Eyoucms v1.4.1 allows authenticated attackers to execute…
- CVE-2020-219301 PoCA stored cross site scripting (XSS) vulnerability in the web_attr_2 field of Eyoucms v1.4.1 allows authenticated attackers to execute…
- CVE-2020-219322 PoCsA vulnerability in /Login.html of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to bypass login and obtain a…
- CVE-2020-219332 PoCsAn issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private key could be found…
- CVE-2020-219342 PoCsAn issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where authentication to download the Syslog could be…
- CVE-2020-219352 PoCsA command injection vulnerability in HNAP1/GetNetworkTomographySettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows…
- CVE-2020-219362 PoCsAn issue in HNAP1/GetMultipleHNAPs of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to access the components…
- CVE-2020-219372 PoCsAn command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows…
- CVE-2020-219671 PoCFile upload vulnerability in the Catalog feature in Prestashop 1.7.6.7 allows remote attackers to run arbitrary code via the add new file…
- CVE-2020-219761 PoCAn arbitrary file upload in the <input type="file" name="user_image"> component of NewsOne CMS v1.1.0 allows attackers to webshell and…
- CVE-2020-219872 PoCsHomeAutomation 3.3.2 is affected by persistent Cross Site Scripting (XSS). XSS vulnerabilities occur when input passed via several…
- CVE-2020-219892 PoCsHomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform certain actions…
- CVE-2020-219902 PoCsEmmanuel MyDomoAtHome (MDAH) REST API REST API Domoticz ISS Gateway 0.2.40 is affected by an information disclosure vulnerability due to…
- CVE-2020-219912 PoCsAVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the…
- CVE-2020-219921 PoCInim Electronics SmartLiving SmartLAN/G/SI <=6.x suffers from an authenticated remote command injection vulnerability. The issue exist due…
- CVE-2020-219931 PoCIn WEMS Limited Enterprise Manager 2.58, input passed to the GET parameter 'email' is not properly sanitized before being returned to the…
- CVE-2020-219942 PoCsAVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a…
- CVE-2020-219951 PoCInim Electronics Smartliving SmartLAN/G/SI <=6.x uses default hardcoded credentials. An attacker could exploit this to gain Telnet, SSH…
- CVE-2020-219962 PoCsAVE DOMINAplus <=1.10.x suffers from an unauthenticated reboot command execution. Attackers can exploit this issue to cause a denial of…
- CVE-2020-219972 PoCsSmartwares HOME easy <=1.0.9 is vulnerable to an unauthenticated database backup download and information disclosure vulnerability. An…
- CVE-2020-219982 PoCsIn HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to…
- CVE-2020-219992 PoCsiWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using default credentials.…