CVE-2020-26000 to CVE-2020-26999
93 CVEs with public proof-of-concept exploits.
- CVE-2020-260451 PoCFUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to…
- CVE-2020-260491 PoCNifty-PM CPE 2.3 is affected by stored HTML injection. The impact is remote arbitrary code execution.
- CVE-2020-260501 PoCSaferVPN for Windows Ver 5.0.3.3 through 5.0.4.15 could allow local privilege escalation from low privileged users to SYSTEM via a crafted…
- CVE-2020-260511 PoCCollege Management System Php 1.0 suffers from SQL injection vulnerabilities in the index.php page from POST parameters 'unametxt' and…
- CVE-2020-260521 PoCOnline Marriage Registration System 1.0 is affected by stored cross-site scripting (XSS) vulnerabilities in multiple parameters.
- CVE-2020-260611 PoCClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerability. The…
- CVE-2020-260731 PoCCisco SD-WAN vManage Directory Traversal Vulnerability
- CVE-2020-261242 PoCsopenmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of…
- CVE-2020-261301 PoCIssues were discovered in Open TFTP Server multithreaded 1.66 and Open TFTP Server single port 1.66. Due to insufficient access…
- CVE-2020-261311 PoCIssues were discovered in Open DHCP Server (Regular) 1.75 and Open DHCP Server (LDAP Based) 0.1Beta. Due to insufficient access…
- CVE-2020-261532 PoCsA cross-site scripting (XSS) vulnerability in…
- CVE-2020-261601 PoCjwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m["aud"] (which is…
- CVE-2020-261631 PoCBigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim…
- CVE-2020-261652 PoCsqdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in…
- CVE-2020-261711 PoCIn tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated. By…
- CVE-2020-261721 PoCEvery login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse the token when a…
- CVE-2020-261731 PoCAn incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by…
- CVE-2020-261741 PoCtangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes…
- CVE-2020-261751 PoCIn tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to change…
- CVE-2020-261761 PoCAn issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the…
- CVE-2020-261771 PoCIn tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not intended to be edited…
- CVE-2020-261781 PoCIn tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being…
- CVE-2020-262011 PoCAskey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level. This allows an…
- CVE-2020-262082 PoCsHeap-buffer-overflow in jhead
- CVE-2020-262141 PoCLDAP authentication bypass in Alerta
- CVE-2020-262179 PoCsRemote Code Execution in XStream
- CVE-2020-262181 PoCHTML Injection in touchbase.ai
- CVE-2020-262261 PoCSecret disclosure in semantic-release
- CVE-2020-262333 PoCsRemote Code Execution in Git Credential Manager Core
- CVE-2020-262382 PoCsCritical vulnerability found in cron-utils
- CVE-2020-262421 PoCDenial of service in geth
- CVE-2020-262482 PoCsBlind SQL injection during the CommentGrade process
- CVE-2020-262561 PoCDenial of service in fast-csv
- CVE-2020-262586 PoCsServer-Side Forgery Request can be activated unmarshalling with XStream
- CVE-2020-262595 PoCsXStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling
- CVE-2020-262821 PoCTemplate Injection in BrowserUp Proxy
- CVE-2020-263011 PoCCommand injection in mscdex/ssh2
- CVE-2020-263021 PoCis.js is a general-purpose check library. Versions 0.9.0 and prior contain one or more regular expressions that are vulnerable to Regular…
- CVE-2020-263031 PoCGHSL-2020-289: Regular Expression Denial of Service (ReDoS) in insane
- CVE-2020-263041 PoCGHSL-2020-290: Regular Expression Denial of Service (ReDoS) in foundation-sites
- CVE-2020-263081 PoCGHSL-2020-302: Regular Expression Denial of Service (ReDoS) in validate.js
- CVE-2020-263111 PoCGHSL-2020-312: Regular Expression Denial of Service (ReDoS) in useragent
- CVE-2020-264135 PoCsAn issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL…
- CVE-2020-265091 PoCAirleader Master and Easy <= 6.21 devices have default credentials that can be used for a denial of service.
- CVE-2020-265151 PoCAn insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie…
- CVE-2020-265161 PoCA CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not…
- CVE-2020-265251 PoCDamstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the database and server to…
- CVE-2020-265261 PoCAn issue was discovered in Damstra Smart Asset 2020.7. It is possible to enumerate valid usernames on the login page. The application…
- CVE-2020-265271 PoCAn issue was discovered in API/api/Version in Damstra Smart Asset 2020.7. Cross-origin resource sharing trusts random origins by accepting…
- CVE-2020-265541 PoCREDDOXX MailDepot 2033 (aka 2.3.3022) allows XSS via an incoming HTML e-mail message.
- CVE-2020-265611 PoCBelkin LINKSYS WRT160NL 1.0.04.002_US_20130619 devices have a stack-based buffer overflow vulnerability because of sprintf in create_dir…
- CVE-2020-265631 PoCObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is…
- CVE-2020-265641 PoCObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a…
- CVE-2020-265651 PoCObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. This can be used to…
- CVE-2020-265661 PoCA Denial of Service condition in Motion-Project Motion 3.2 through 4.3.1 allows remote unauthenticated users to cause a webu.c…
- CVE-2020-265674 PoCsAn issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without…
- CVE-2020-265741 PoCLeostream Connection Broker 8.2.x is affected by stored XSS. An unauthenticated attacker can inject arbitrary JavaScript code via the…
- CVE-2020-266231 PoCSQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the…
- CVE-2020-266241 PoCA SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web…
- CVE-2020-266251 PoCA SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web…
- CVE-2020-266271 PoCA Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database…
- CVE-2020-266281 PoCA Cross-Site Scripting (XSS) vulnerability was discovered in Hospital Management System V4.0 which allows an attacker to execute arbitrary…
- CVE-2020-266291 PoCA JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an…
- CVE-2020-266301 PoCA Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database…
- CVE-2020-266521 PoCAn issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of service.
- CVE-2020-266681 PoCA SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated…
- CVE-2020-266691 PoCA stored cross-site scripting (XSS) vulnerability was discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker…
- CVE-2020-266701 PoCA vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands…
- CVE-2020-266721 PoCTestimonial Rotator Wordpress Plugin 3.0.2 is affected by Cross Site Scripting (XSS) in /wp-admin/post.php. If a user intercepts a request…
- CVE-2020-266821 PoCIn libass 0.14.0, the `ass_outline_construct`'s call to `outline_stroke` causes a signed integer overflow.
- CVE-2020-267011 PoCCross-site scripting (XSS) vulnerability in Dashboards section in Kaa IoT Platform v1.2.0 allows remote attackers to inject malicious web…
- CVE-2020-267071 PoCAn issue was discovered in the add function in Shenzhim AAPTJS 1.3.1 which allows attackers to execute arbitrary code via the filePath…
- CVE-2020-267121 PoCREDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a…
- CVE-2020-267131 PoCREDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort. The information submitted by the user is…
- CVE-2020-267281 PoCA vulnerability was discovered in Tenda AC9 v3.0 V15.03.06.42_multi and Tenda AC9 V1.0 V15.03.05.19(6318)_CN which allows for remote code…
- CVE-2020-267321 PoCSKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 does not set the Secure flag for the session cookie in an HTTPS…
- CVE-2020-267331 PoCCross Site Scripting (XSS) in Configuration page in SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 allows…
- CVE-2020-267661 PoCA Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login and User…
- CVE-2020-267971 PoCMediainfo before version 20.08 has a heap buffer overflow vulnerability via MediaInfoLib::File_Gxf::ChooseParser_ChannelGrouping.
- CVE-2020-268021 PoCforma.lms 2.3.0.2 is affected by Cross Site Request Forgery (CSRF) in formalms/appCore/index.php?r=lms/profile/show&ap=saveinfo via a GET…
- CVE-2020-268061 PoCadmin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code…
- CVE-2020-268082 PoCsSAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4…
- CVE-2020-268322 PoCsSAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752,…
- CVE-2020-268361 PoCSAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect…
- CVE-2020-268761 PoCThe wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for course videos and…
- CVE-2020-268782 PoCsRuckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API…
- CVE-2020-268792 PoCsRuckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact…
- CVE-2020-268861 PoCSoftaculous before 5.5.7 is affected by a code execution vulnerability because of External Initialization of Trusted Variables or Data…
- CVE-2020-268872 PoCsFRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism.
- CVE-2020-269191 PoCKEVNETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level.
- CVE-2020-269352 PoCsAn issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered…
- CVE-2020-269482 PoCsEmby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
- CVE-2020-269503 PoCsIn certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free…