CVE-2020-25000 to CVE-2020-25999
111 CVEs with public proof-of-concept exploits.
- CVE-2020-250041 PoCHeybbs v1.2 has a SQL injection vulnerability in user.php file via the ID parameter which may allow a remote attacker to execute arbitrary…
- CVE-2020-250051 PoCHeybbs v1.2 has a SQL injection vulnerability in msg.php file via the ID parameter which may allow a remote attacker to execute arbitrary…
- CVE-2020-250061 PoCHeybbs v1.2 has a SQL injection vulnerability in login.php file via the username parameter which may allow a remote attacker to execute…
- CVE-2020-250152 PoCsA specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and…
- CVE-2020-250191 PoCjitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL…
- CVE-2020-250341 PoCeMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort, sort_by,…
- CVE-2020-250424 PoCsAn arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authenticated…
- CVE-2020-250682 PoCsSetelsa Conacwin v3.7.1.2 is vulnerable to a local file inclusion vulnerability. This vulnerability allows a remote unauthenticated…
- CVE-2020-250787 PoCsKEVAn issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser…
- CVE-2020-251062 PoCsNanosystems SupRemo 4.1.3.2348 allows attackers to obtain LocalSystem access because File Manager can be used to rename Supremo.exe and…
- CVE-2020-251341 PoCAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local…
- CVE-2020-252002 PoCsPritunl 1.29.2145.25 allows attackers to enumerate valid VPN usernames via a series of /auth/session login attempts. Initially, the server…
- CVE-2020-252031 PoCThe Framer Preview application 12 for Android exposes com.framer.viewer.FramerViewActivity to other applications. By calling the intent…
- CVE-2020-252041 PoCThe God Kings application 0.60.1 for Android exposes a broadcast receiver to other apps called…
- CVE-2020-252111 PoCIn the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing…
- CVE-2020-2521322 PoCsKEVThe File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code…
- CVE-2020-252236 PoCsKEVA remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
- CVE-2020-252651 PoCAppImage libappimage before 1.0.3 allows attackers to trigger an overwrite of a system-installed .desktop file by providing a .desktop…
- CVE-2020-252671 PoCAn XSS issue exists in the question-pool file-upload preview feature in ILIAS 6.4.
- CVE-2020-252681 PoCRemote Code Execution can occur via the external news feed in ILIAS 6.4 because of incorrect parameter sanitization for Magpie RSS data.
- CVE-2020-252702 PoCsPHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City.
- CVE-2020-252861 PoCIn wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments…
- CVE-2020-252872 PoCsPligg 2.0.3 allows remote authenticated users to execute arbitrary commands because the template editor can edit any file, as demonstrated…
- CVE-2020-252881 PoCAn issue was discovered in MantisBT before 2.24.3. When editing an Issue in a Project where a Custom Field with a crafted Regular…
- CVE-2020-253431 PoCCross-site scripting (XSS) vulnerabilities in Symphony CMS 3.0.0 allow remote attackers to inject arbitrary web script or HTML to…
- CVE-2020-253621 PoCThe id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injection in the…
- CVE-2020-253851 PoCNagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapshot through the…
- CVE-2020-253981 PoCCSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.
- CVE-2020-253991 PoCStored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the…
- CVE-2020-254121 PoCcom_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code execution.
- CVE-2020-254493 PoCsCross Site Scripting (XSS) vulnerability in Arachnys Cabot 0.11.12 can be exploited via the Address column.
- CVE-2020-254533 PoCsAn issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code…
- CVE-2020-254541 PoCCross-site Scripting (XSS) vulnerability in grocy 2.7.1 via the add recipe module, which gets executed when deleting the recipe.
- CVE-2020-254611 PoCInvalid Memory Access in the fxProxyGetter function in moddable/xs/sources/xsProxy.c in Moddable SDK before OS200908 causes a denial of…
- CVE-2020-254621 PoCHeap buffer overflow in the fxCheckArrowFunction function at moddable/xs/sources/xsSyntaxical.c:3562 in Moddable SDK before OS200903.
- CVE-2020-254631 PoCInvalid Memory Access in fxUTF8Decode at moddable/xs/sources/xsCommon.c:916 in Moddable SDK before OS200908 causes a denial of service…
- CVE-2020-254641 PoCHeap buffer overflow at moddable/xs/sources/xsDebug.c in Moddable SDK before before 20200903. The top stack frame is only partially…
- CVE-2020-254651 PoCNull Pointer Dereference. in xObjectBindingFromExpression at moddable/xs/sources/xsSyntaxical.c:3419 in Moddable SDK before OS200908…
- CVE-2020-254661 PoCA SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and…
- CVE-2020-254672 PoCsA null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker to cause a denial of…
- CVE-2020-254831 PoCAn arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain…
- CVE-2020-254891 PoCA heap overflow in Sqreen PyMiniRacer (aka Python Mini Racer) before 0.3.0 allows remote attackers to potentially exploit heap corruption.
- CVE-2020-254943 PoCsXinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or…
- CVE-2020-254954 PoCsA reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote attackers to inject…
- CVE-2020-254983 PoCsCross Site Scripting (XSS) vulnerability in Beetel router 777VR1 can be exploited via the NTP server name in System Time and "Keyword" in…
- CVE-2020-255063 PoCsKEVD-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote…
- CVE-2020-255071 PoCAn incorrect permission assignment during the installation script of TeamworkCloud 18.0 thru 19.0 allows a local unprivileged attacker to…
- CVE-2020-255161 PoCWSO2 Enterprise Integrator 6.6.0 or earlier contains a stored cross-site scripting (XSS) vulnerability in BPMN explorer tasks.
- CVE-2020-255331 PoCAn issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged action within the…
- CVE-2020-255383 PoCsAn authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code…
- CVE-2020-255408 PoCsThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on a remote server…
- CVE-2020-255573 PoCsIn CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when…
- CVE-2020-255601 PoCIn SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the…
- CVE-2020-255611 PoCSapphireIMS 5 utilized default sapphire:ims credentials to connect the client to server. This credential is saved in ServerConf.config…
- CVE-2020-255621 PoCIn SapphireIMS 5.0, there is no CSRF token present in the entire application. This can lead to CSRF vulnerabilities in critical…
- CVE-2020-255631 PoCIn SapphireIMS 5.0, it is possible to create local administrator on any client without requiring any credentials by directly accessing…
- CVE-2020-255641 PoCIn SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user by directly…
- CVE-2020-255651 PoCIn SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the…
- CVE-2020-255661 PoCIn SapphireIMS 5.0, it is possible to take over an account by sending a request to the Save_Password form as shown in POC. Notice that we…
- CVE-2020-255921 PoCIn SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke…
- CVE-2020-256131 PoCAn issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with…
- CVE-2020-256271 PoCThe moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed…
- CVE-2020-256371 PoCA double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about…
- CVE-2020-256561 PoCA flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and…
- CVE-2020-256631 PoCA call to ConformPixelInfo() in the SetImageAlphaChannel() routine of /MagickCore/channel.c caused a subsequent heap-use-after-free or…
- CVE-2020-256682 PoCsA flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free…
- CVE-2020-256692 PoCsA vulnerability was found in the Linux Kernel where the function sunkbd_reinit having been scheduled by sunkbd_interrupt before sunkbd…
- CVE-2020-256842 PoCsA flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the…
- CVE-2020-256852 PoCsA flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(),…
- CVE-2020-256862 PoCsA flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending request for the…
- CVE-2020-257052 PoCsA flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote…
- CVE-2020-257361 PoCAcronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service…
- CVE-2020-257441 PoCSaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could cause a denial of…
- CVE-2020-257511 PoCThe paGO Commerce plugin 2.5.9.0 for Joomla! allows SQL Injection via the administrator/index.php?option=com_pago&view=comments…
- CVE-2020-257521 PoCAn issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the installer and…
- CVE-2020-257531 PoCAn issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to the last 6 digits of…
- CVE-2020-257541 PoCAn issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents…
- CVE-2020-257551 PoCAn issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /installer/upgrade_start…
- CVE-2020-257605 PoCsProjectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid'…
- CVE-2020-257614 PoCsProjectworlds Visitor Management System in PHP 1.0 allows XSS. The file myform.php does not perform input validation on the request…
- CVE-2020-257623 PoCsAn issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the…
- CVE-2020-257632 PoCsSeat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote…
- CVE-2020-257801 PoCIn CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal…
- CVE-2020-257821 PoCAn issue was discovered on Accfly Wireless Security IR Camera 720P System with software versions v3.10.73 through v4.15.77. There is an…
- CVE-2020-257831 PoCAn issue was discovered on Accfly Wireless Security IR Camera System 720P with software versions v3.10.73 through v4.15.77. There is an…
- CVE-2020-257841 PoCAn issue was discovered on Accfly Wireless Security IR Camera System 720P with software versions v3.10.73 through v4.15.77. There is an…
- CVE-2020-257861 PoCwebinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This…
- CVE-2020-257872 PoCsAn issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting them.
- CVE-2020-257903 PoCsTypesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the…
- CVE-2020-258202 PoCsBigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document…
- CVE-2020-258301 PoCAn issue was discovered in MantisBT before 2.24.3. Improper escaping of a custom field's name allows an attacker to inject HTML and, if…
- CVE-2020-258581 PoCThe QCMAP_Web_CLIENT binary in the Qualcomm QCMAP software suite prior to versions released in October 2020 does not validate the return…
- CVE-2020-258591 PoCThe QCMAP_CLI utility in the Qualcomm QCMAP software suite prior to versions released in October 2020 uses a system() call without…
- CVE-2020-258602 PoCsThe install.c module in the Pengutronix RAUC update client prior to version 1.5 has a Time-of-Check Time-of-Use vulnerability, where…
- CVE-2020-258642 PoCsHashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scripting. Fixed in 1.9.5,…
- CVE-2020-258671 PoCSoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to get access without…
- CVE-2020-258891 PoCOnline Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on…
- CVE-2020-258901 PoCThe web application of Kyocera printer (ECOSYS M2640IDW) is affected by Stored XSS vulnerability, discovered in the addition a new contact…
- CVE-2020-259013 PoCsHost Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with…
- CVE-2020-259052 PoCsAn SQL Injection vulnerabilty exists in Sourcecodester Mobile Shop System in PHP MySQL 1.0 via the email parameter in (1) login.php or (2)…
- CVE-2020-259171 PoCStratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform, for example a…
- CVE-2020-259251 PoCCross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient 10.3.5 allows remote attackers to inject arbitrary web script or HTML…
- CVE-2020-259501 PoCAdvanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact from the My…
- CVE-2020-259523 PoCsSQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote…
- CVE-2020-259551 PoCSourceCodester Student Management System Project in PHP version 1.0 is vulnerable to stored a cross-site scripting (XSS) via the 'add…
- CVE-2020-259671 PoCThe member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vulnerability.
- CVE-2020-259851 PoCMonoCMS Blog 1.0 is affected by: Arbitrary File Deletion. Any authenticated user can delete files on and off the webserver (php files can…
- CVE-2020-259861 PoCA Cross Site Request Forgery (CSRF) vulnerability in MonoCMS Blog 1.0 allows attackers to change the password of a user.
- CVE-2020-259871 PoCMonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is bcrypt and hashcat…
- CVE-2020-259882 PoCsUPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' which leaks the…
- CVE-2020-259901 PoCWebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Exploiting this issue…