CVE-2020-22000 to CVE-2020-22999
85 CVEs with public proof-of-concept exploits.
- CVE-2020-220002 PoCsHomeAutomation 3.3.2 suffers from an authenticated OS command execution vulnerability using custom command v0.1 plugin. This can be…
- CVE-2020-220012 PoCsHomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header…
- CVE-2020-220021 PoCAn Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI <=6.x within the…
- CVE-2020-220151 PoCBuffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c, which could let a…
- CVE-2020-220161 PoCA heap-based Buffer Overflow vulnerability in FFmpeg 4.2 at libavcodec/get_bits.h when writing .mov files, which might lead to memory…
- CVE-2020-220171 PoCA heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at ff_fill_rectangle in libavfilter/drawutils.c, which might lead to…
- CVE-2020-220191 PoCBuffer Overflow vulnerability in FFmpeg 4.2 at convolution_y_10bit in libavfilter/vf_vmafmotion.c, which could let a remote malicious user…
- CVE-2020-220201 PoCBuffer Overflow vulnerability in FFmpeg 4.2 in the build_diff_map function in libavfilter/vf_fieldmatch.c, which could let a remote…
- CVE-2020-220211 PoCBuffer Overflow vulnerability in FFmpeg 4.2 at filter_edges function in libavfilter/vf_yadif.c, which could let a remote malicious user…
- CVE-2020-220221 PoCA heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_fieldorder.c, which might lead to memory…
- CVE-2020-220241 PoCBuffer Overflow vulnerability in FFmpeg 4.2 at the lagfun_frame16 function in libavfilter/vf_lagfun.c, which could let a remote malicious…
- CVE-2020-220251 PoCA heap-based Buffer Overflow vulnerability exists in gaussian_blur at libavfilter/vf_edgedetect.c, which might lead to memory corruption…
- CVE-2020-220261 PoCBuffer Overflow vulnerability exists in FFmpeg 4.2 in the config_input function at libavfilter/af_tremolo.c, which could let a remote…
- CVE-2020-220271 PoCA heap-based Buffer Overflow vulnerability exits in FFmpeg 4.2 in deflate16 at libavfilter/vf_neighbor.c, which might lead to memory…
- CVE-2020-220281 PoCBuffer Overflow vulnerability exists in FFmpeg 4.2 in filter_vertically_8 at libavfilter/vf_avgblur.c, which could cause a remote Denial…
- CVE-2020-220291 PoCA heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_colorconstancy.c: in slice_get_derivative, which…
- CVE-2020-220311 PoCA Heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_w3fdif.c in filter16_complex_low, which might lead to…
- CVE-2020-220321 PoCA heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_edgedetect.c in gaussian_blur, which might lead to memory…
- CVE-2020-220331 PoCA heap-based Buffer Overflow Vulnerability exists FFmpeg 4.2 at libavfilter/vf_vmafmotion.c in convolution_y_8bit, which could let a…
- CVE-2020-220341 PoCA heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_floodfill.c, which might lead to memory corruption and…
- CVE-2020-220351 PoCA heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in get_block_row at libavfilter/vf_bm3d.c, which might lead to memory…
- CVE-2020-220361 PoCA heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_intra at libavfilter/vf_bwdif.c, which might lead to memory…
- CVE-2020-220371 PoCA Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context3 at options.c.
- CVE-2020-220381 PoCA Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_v4l2_m2m_create_context function in v4l2_m2m.c.
- CVE-2020-220391 PoCA Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the inavi_add_ientry function.
- CVE-2020-220401 PoCA Denial of Service vulnerability exists in FFmpeg 4.2 idue to a memory leak in the v_frame_alloc function in frame.c.
- CVE-2020-220411 PoCA Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_buffersrc_add_frame_flags function in buffersrc.
- CVE-2020-220421 PoCA Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak is affected by: memory leak in the link_filter_inouts function…
- CVE-2020-220431 PoCA Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak at the fifo_alloc_common function in libavutil/fifo.c.
- CVE-2020-220441 PoCA Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the url_open_dyn_buf_internal function in…
- CVE-2020-220461 PoCA Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_allocl function in…
- CVE-2020-220481 PoCA Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_frame_pool_get function in framepool.c.
- CVE-2020-220491 PoCA Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the wtvfile_open_sector function in wtvdec.c.
- CVE-2020-220511 PoCA Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the filter_frame function in vf_tile.c.
- CVE-2020-220541 PoCA Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_dict_set function in dict.c.
- CVE-2020-220561 PoCA Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the config_input function in af_acrossover.c.
- CVE-2020-220791 PoCStack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute…
- CVE-2020-220832 PoCsjsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note:…
- CVE-2020-221221 PoCA SQL injection vulnerability in /oa.php?c=Staff&a=read of Find a Place LJCMS v 1.3 allows attackers to access sensitive database…
- CVE-2020-221481 PoCA stored cross site scripting (XSS) vulnerability in /admin.php?page=tags of Piwigo 2.10.1 allows attackers to execute arbitrary web…
- CVE-2020-221501 PoCA cross site scripting (XSS) vulnerability in /admin.php?page=permalinks of Piwigo 2.10.1 allows attackers to execute arbitrary web…
- CVE-2020-221651 PoCPHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users…
- CVE-2020-221982 PoCsSQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.
- CVE-2020-222001 PoCDirectory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword.
- CVE-2020-222011 PoCphpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.
- CVE-2020-222031 PoCSQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php.
- CVE-2020-222082 PoCsSQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.
- CVE-2020-222093 PoCsSQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.
- CVE-2020-222103 PoCsSQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.
- CVE-2020-222113 PoCsSQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.
- CVE-2020-222491 PoCRemote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file,…
- CVE-2020-222511 PoCCross Site Scripting (XSS) vulnerability in phpList 3.5.3 via the login name field in Manage Administrators when adding a new admin.
- CVE-2020-223121 PoCA cross-site scripting (XSS) vulnerability was discovered in the OJ/admin-tool /cal_scores.php function of HZNUOJ v1.0.
- CVE-2020-223521 PoCThe gf_dash_segmenter_probe_input function in GPAC v0.8 allows attackers to cause a denial of service (NULL pointer dereference) via a…
- CVE-2020-224211 PoC74CMS v6.0.4 was discovered to contain a cross-site scripting (XSS) vulnerability via /index.php?m=&c=help&a=help_list&key.
- CVE-2020-224271 PoCNagiosXI 5.6.11 is affected by a remote code execution (RCE) vulnerability. An authenticated nagiosadmin user can inject additional…
- CVE-2020-224751 PoC"Tasks" application version before 9.7.3 is affected by insecure permissions. The VoiceCommandActivity application component allows…
- CVE-2020-225501 PoCVeno File Manager 3.5.6 is affected by a directory traversal vulnerability. Using the traversal allows an attacker to download sensitive…
- CVE-2020-226281 PoCBuffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp.
- CVE-2020-226691 PoCModsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment…
- CVE-2020-226731 PoCMemory leak in the senc_Parse function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.
- CVE-2020-226741 PoCAn issue was discovered in gpac 0.8.0. An invalid memory dereference exists in the function FixTrackID located in isom_intern.c, which…
- CVE-2020-226751 PoCAn issue was discovered in gpac 0.8.0. The GetGhostNum function in stbl_read.c has a heap-based buffer overflow which can lead to a denial…
- CVE-2020-226771 PoCAn issue was discovered in gpac 0.8.0. The dump_data_hex function in box_dump.c has a heap-based buffer overflow which can lead to a…
- CVE-2020-226781 PoCAn issue was discovered in gpac 0.8.0. The gf_media_nalu_remove_emulation_bytes function in av_parsers.c has a heap-based buffer overflow…
- CVE-2020-226791 PoCMemory leak in the sgpd_parse_entry function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted…
- CVE-2020-227211 PoCA File Upload Vulnerability in PNotes - Andrey Gruber PNotes.NET v3.8.1.2 allows a local attacker to execute arbitrary code via the…
- CVE-2020-227221 PoCRapid Software LLC Rapid SCADA 5.8.0 is affected by a local privilege escalation vulnerability in the ScadaAgentSvc.exe executable file.…
- CVE-2020-228071 PoCAn issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.
- CVE-2020-228091 PoCIn Windscribe v1.83 Build 20, 'WindscribeService' has an Unquoted Service Path that facilitates privilege escalation.
- CVE-2020-228181 PoCMKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter.
- CVE-2020-228191 PoCMKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.
- CVE-2020-228201 PoCMKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.
- CVE-2020-228393 PoCsReflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers…
- CVE-2020-228403 PoCsOpen redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an…
- CVE-2020-228412 PoCsStored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin…
- CVE-2020-228642 PoCsA cross site scripting (XSS) vulnerability in the Insert Video function of Froala WYSIWYG Editor 3.1.0 allows attackers to execute…
- CVE-2020-228741 PoCInteger overflow vulnerability in function Jsi_ObjArraySizer in jsish before 3.0.8, allows remote attackers to execute arbitrary code.
- CVE-2020-228751 PoCInteger overflow vulnerability in function Jsi_ObjSetLength in jsish before 3.0.6, allows remote attackers to execute arbitrary code.
- CVE-2020-228761 PoCBuffer Overflow vulnerability in quickjs.c in QuickJS, allows remote attackers to cause denial of service. This issue is resolved in the…
- CVE-2020-228821 PoCIssue was discovered in the fxParserTree function in moddable, allows attackers to cause denial of service via a crafted payload. Fixed in…
- CVE-2020-228841 PoCBuffer overflow vulnerability in function jsvGetStringChars in Espruino before RELEASE_2V09, allows remote attackers to execute arbitrary…
- CVE-2020-228851 PoCBuffer overflow vulnerability in mujs before 1.0.8 due to recursion in the GC scanning phase, allows remote attackers to cause a denial of…
- CVE-2020-228861 PoCBuffer overflow vulnerability in function jsG_markobject in jsgc.c in mujs before 1.0.8, allows remote attackers to cause a denial of…
- CVE-2020-229071 PoCStack overflow vulnerability in function jsi_evalcode_sub in jsish before 3.0.18, allows remote attackers to cause a Denial of Service via…