CVE-2020-24000 to CVE-2020-24999
138 CVEs with public proof-of-concept exploits.
- CVE-2020-240001 PoCSQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the…
- CVE-2020-240031 PoCMicrosoft Skype through 8.59.0.77 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's…
- CVE-2020-240081 PoCUmanni RH 1.0 has a user enumeration vulnerability. This issue occurs during password recovery, where a difference in messages could allow…
- CVE-2020-240261 PoCTinyShop, a free and open source mall based on RageFrame2, has a stored XSS vulnerability that affects version 1.2.0. TinyShop allows XSS…
- CVE-2020-240271 PoCIn Live Networks, Inc., liblivemedia version 20200625, there is a potential buffer overflow bug in the server handling of a RTSP "PLAY"…
- CVE-2020-240282 PoCsForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user…
- CVE-2020-240292 PoCsBecause of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can be accessed via a…
- CVE-2020-240302 PoCsForLogic Qualiex v1 and v3 has weak token expiration. This allows remote unauthenticated privilege escalation and access to sensitive data…
- CVE-2020-240332 PoCsAn issue was discovered in fs.com S3900 24T4S 1.7.0 and earlier. The form does not have an authentication or token authentication…
- CVE-2020-240341 PoCSagemcom F@ST 5280 routers using firmware version 1.150.61 have insecure deserialization that allows any authenticated user to perform a…
- CVE-2020-240362 PoCsPHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute…
- CVE-2020-240381 PoCmyFax version 229 logs sensitive information in the export log module which allows any user to access critical information.
- CVE-2020-240451 PoCA sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing…
- CVE-2020-240461 PoCA sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing…
- CVE-2020-240882 PoCsAn issue was discovered in MmMapIoSpace routine in Foxconn Live Update Utility 2.1.6.26, allows local attackers to escalate privileges.
- CVE-2020-240891 PoCAn issue was discovered in ImfHpRegFilter.sys in IOBit Malware Fighter version 8.0.2, allows local attackers to cause a denial of service…
- CVE-2020-241041 PoCXSS on the PIX-Link Repeater/Router LV-WR07 with firmware v28K.Router.20170904 allows attackers to steal credentials without being…
- CVE-2020-241151 PoCIn projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access.
- CVE-2020-241191 PoCA heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.
- CVE-2020-241351 PoCA Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Wcms 0.3.2, which allows remote attackers to inject arbitrary web…
- CVE-2020-241361 PoCDirectory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the pagename…
- CVE-2020-241381 PoCCross Site Scripting (XSS) vulnerability in wcms 0.3.2 allows remote attackers to inject arbitrary web script and HTML via the pagename…
- CVE-2020-241401 PoCServer-side request forgery in Wcms 0.3.2 let an attacker send crafted requests from the back-end server of a vulnerable web application…
- CVE-2020-241482 PoCsServer-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in…
- CVE-2020-241752 PoCsBuffer overflow in Yz1 0.30 and 0.32, as used in IZArc 4.4, ZipGenius 6.3.2.3116, and Explzh (extension) 8.14, allows attackers to execute…
- CVE-2020-2418616 PoCsA Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated…
- CVE-2020-241871 PoCAn issue was discovered in ecma-helpers.c in jerryscript version 2.3.0, allows local attackers to cause a denial of service (DoS) (Null…
- CVE-2020-241931 PoCA SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication…
- CVE-2020-241941 PoCA Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to…
- CVE-2020-241961 PoCAn Arbitrary File Upload in Vehicle Image Upload in Online Bike Rental v1.0 allows authenticated admin to conduct remote code execution.
- CVE-2020-242081 PoCA SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to bypass the…
- CVE-2020-242131 PoCAn integer overflow was discovered in YGOPro ygocore v13.51. Attackers can use it to leak the game server thread's memory.
- CVE-2020-242143 PoCsAn issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a crafted…
- CVE-2020-242153 PoCsAn issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded…
- CVE-2020-242175 PoCsAn issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not…
- CVE-2020-242192 PoCsAn issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests…
- CVE-2020-242211 PoCAn issue was discovered in GetByte function in miniupnp ngiflib version 0.4, allows local attackers to cause a denial of service (DoS) via…
- CVE-2020-242234 PoCsMara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.
- CVE-2020-242271 PoCPlayground Sessions v2.5.582 (and earlier) for Windows, stores the user credentials in plain text allowing anyone with access to…
- CVE-2020-242411 PoCIn Netwide Assembler (NASM) 2.15rc10, there is heap use-after-free in saa_wbytes in nasmlib/saa.c.
- CVE-2020-242421 PoCIn Netwide Assembler (NASM) 2.15rc10, SEGV can be triggered in tok_text in asm/preproc.c by accessing READ memory.
- CVE-2020-242651 PoCAn issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in MemcmpInterceptorCommon() that can…
- CVE-2020-242661 PoCAn issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in get_l2len() that can make tcpprep…
- CVE-2020-242852 PoCsINTELBRAS TELEFONE IP TIP200 version 60.61.75.22 allows an attacker to obtain sensitive information through /cgi-bin/cgiServer.exx.
- CVE-2020-242971 PoChttpd on TP-Link TL-WPA4220 devices (versions 2 through 4) allows remote authenticated users to execute arbitrary OS commands by sending…
- CVE-2020-243011 PoCUsers of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability in this module,…
- CVE-2020-243121 PoCmndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This…
- CVE-2020-243421 PoCLua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in…
- CVE-2020-243431 PoCArtifex MuJS through 1.0.7 has a use-after-free in jsrun.c because of unconditional marking in jsgc.c.
- CVE-2020-243441 PoCJerryScript through 2.3.0 has a (function({a=arguments}){const arguments}) buffer over-read.
- CVE-2020-243451 PoCJerryScript through 2.3.0 allows stack consumption via function a(){new new Proxy(a,{})}JSON.parse("[]",a). NOTE: the vendor states that…
- CVE-2020-243461 PoCnjs through 0.4.3, used in NGINX, has a use-after-free in njs_json_parse_iterator_call in njs_json.c.
- CVE-2020-243471 PoCnjs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_lvlhsh_level_find in njs_lvlhsh.c.
- CVE-2020-243481 PoCnjs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_json_stringify_iterator in njs_json.c.
- CVE-2020-243491 PoCnjs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. NOTE: the vendor considers the issue to…
- CVE-2020-243631 PoCKEVTP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST…
- CVE-2020-243652 PoCsAn issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows…
- CVE-2020-243703 PoCsldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
- CVE-2020-243721 PoCLuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c.
- CVE-2020-243792 PoCsWebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
- CVE-2020-243811 PoCGUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it…
- CVE-2020-243871 PoCAn issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explicitly check the…
- CVE-2020-243881 PoCAn issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded…
- CVE-2020-243911 PoCmongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap…
- CVE-2020-243971 PoCAn issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.0.SP-534. An attacker-controlled server can trigger…
- CVE-2020-244902 PoCsImproper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adjacent access. This…
- CVE-2020-245482 PoCsEricom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP…
- CVE-2020-245491 PoCopenMAINT before 1.1-2.4.2 allows remote authenticated users to run arbitrary JSP code on the underlying web server.
- CVE-2020-245502 PoCsAn Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the…
- CVE-2020-245533 PoCsGo before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a Content-Type header.
- CVE-2020-245671 PoCvoidtools Everything before 1.4.1 Beta Nightly 2020-08-18 allows privilege escalation via a Trojan horse urlmon.dll file in the…
- CVE-2020-245713 PoCsNexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal.
- CVE-2020-245722 PoCsAn issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misconfigured (and…
- CVE-2020-245742 PoCsThe client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as of 12:58 AM Eastern, 9/26/21) allows local privilege escalation…
- CVE-2020-245771 PoCAn issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. The One Touch application discloses…
- CVE-2020-245792 PoCsAn issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass…
- CVE-2020-245811 PoCAn issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_cmd.cgi feature…
- CVE-2020-245891 PoCThe Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
- CVE-2020-246093 PoCsTechKshetra Info Solutions Pvt. Ltd Savsoft Quiz 5.5 and earlier has XSS which can result in an attacker injecting the XSS payload in the…
- CVE-2020-246131 PoCwolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_CR state, within SanityCheckTls13MsgReceived() in tls13.c. This is an…
- CVE-2020-246161 PoCFasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to…
- CVE-2020-247002 PoCsOX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.
- CVE-2020-247014 PoCsOX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).
- CVE-2020-247071 PoCGophish before 0.11.0 allows the creation of CSV sheets that contain malicious content.
- CVE-2020-247081 PoCCross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form.
- CVE-2020-247091 PoCCross Site Scripting (XSS) vulnerability in Gophish through 0.10.1 via a crafted landing page or email template.
- CVE-2020-247101 PoCGophish before 0.11.0 allows SSRF attacks.
- CVE-2020-247111 PoCThe Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking…
- CVE-2020-247121 PoCCross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page.
- CVE-2020-247131 PoCGophish through 0.10.1 does not invalidate the gophish cookie upon logout.
- CVE-2020-247161 PoCOpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for all directories.
- CVE-2020-247171 PoCOpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by mode 0770 being…
- CVE-2020-247191 PoCExposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a…
- CVE-2020-247221 PoCAn issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-10-05, as used in COVID-19…
- CVE-2020-247231 PoCCross Site Scripting (XSS) vulnerability in the Registration page of the admin panel in PHPGurukul User Registration & Login and User…
- CVE-2020-247401 PoCAn issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage
- CVE-2020-247501 PoCFasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to…
- CVE-2020-247531 PoCA memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow an attacker to…
- CVE-2020-247551 PoCIn Ubiquiti UniFi Video v3.10.13, when the executable starts, its first library validation is in the current directory. This allows the…
- CVE-2020-247652 PoCsInterMind iMind Server through 3.13.65 allows remote unauthenticated attackers to read the self-diagnostic archive via a direct…
- CVE-2020-247721 PoCIn Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that would launch the…
- CVE-2020-247913 PoCsFUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker…
- CVE-2020-248151 PoCA Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2…
- CVE-2020-248211 PoCA vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a…
- CVE-2020-248411 PoCPNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp. Exploiting this issue could allow an attacker to…
- CVE-2020-248471 PoCA Cross-Site Request Forgery (CSRF) vulnerability is identified in FruityWifi through 2.4. Due to a lack of CSRF protection in…
- CVE-2020-248603 PoCsCMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in…
- CVE-2020-248612 PoCsGetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you…
- CVE-2020-248621 PoCThe catID parameter in Pharmacy Medical Store and Sale Point v1.0 has been found to be vulnerable to a Time-Based blind SQL injection via…
- CVE-2020-248815 PoCsSSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
- CVE-2020-248891 PoCA buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedModel in src/metadata/normalize_model.cpp may lead to…
- CVE-2020-248901 PoClibraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent…
- CVE-2020-248991 PoCNagios XI 5.7.2 is affected by a remote code execution (RCE) vulnerability. An authenticated user can inject additional commands into…
- CVE-2020-249001 PoCThe default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load in file…
- CVE-2020-249011 PoCThe default installation of Krpano Panorama Viewer version <=1.20.8 is vulnerable to Reflected XSS due to insecure remote js load in file…
- CVE-2020-249022 PoCsQuixplorer <=2.4.1 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied input. A remote…
- CVE-2020-249032 PoCsCute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied input. A…
- CVE-2020-249041 PoCAn issue was discovered in attach parameter in GNOME Gmail version 2.5.4, allows remote attackers to gain sensitive information via…
- CVE-2020-249123 PoCsA reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter…
- CVE-2020-249133 PoCsA SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated…
- CVE-2020-249163 PoCsCGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
- CVE-2020-249183 PoCsA buffer overflow in the RTSP service of the Ambarella Oryx RTSP Server 2020-01-07 allows an unauthenticated attacker to send a crafted…
- CVE-2020-249221 PoCCross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to…
- CVE-2020-249301 PoCBeijing Wuzhi Internet Technology Co., Ltd. Wuzhi CMS 4.0.1 is an open source content management system. The five fingers CMS backend…
- CVE-2020-249321 PoCAn SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php.
- CVE-2020-249391 PoCPrototype pollution in Stampit supermixer 1.0.3 allows an attacker to modify the prototype of a base object which can vary in severity…
- CVE-2020-249482 PoCsThe ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file,…
- CVE-2020-249494 PoCsPrivilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to…
- CVE-2020-249553 PoCsSUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore…
- CVE-2020-249632 PoCsAn Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4.
- CVE-2020-249721 PoCThe Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because…
- CVE-2020-249771 PoCGNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue…
- CVE-2020-249781 PoCIn NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit…
- CVE-2020-249821 PoCAn issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. It allows CSRF. An attacker may be able to trick an authenticated…
- CVE-2020-249831 PoCAn issue was discovered in Quadbase EspressReports ES 7 Update 9. An unauthenticated attacker can create a malicious HTML file that houses…
- CVE-2020-249851 PoCAn issue was discovered in Quadbase EspressReports ES 7 Update 9. An authenticated user is able to navigate to the MenuPage section of the…
- CVE-2020-249961 PoCThere is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2. It can be triggered by…
- CVE-2020-249991 PoCThere is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by sending a crafted PDF…