CVE-2020-27000 to CVE-2020-27999
142 CVEs with public proof-of-concept exploits.
- CVE-2020-270161 PoCTrend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a cross-site request forgery (CSRF) vulnerability…
- CVE-2020-270171 PoCTrend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processing (XXE)…
- CVE-2020-270181 PoCTrend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a server side request forgery vulnerability which…
- CVE-2020-270191 PoCTrend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an information disclosure vulnerability which…
- CVE-2020-271311 PoCCisco Security Manager Java Deserialization Vulnerabilities
- CVE-2020-271511 PoCAn issue was discovered in Kata Containers through 1.11.3 and 2.x through 2.0-rc1. The runtime will execute binaries given using…
- CVE-2020-271761 PoCMutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution. NOTE: this might be considered a duplicate of…
- CVE-2020-271912 PoCsLionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted string in the index.php f1…
- CVE-2020-271943 PoCsAn issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or in kernel/bpf/verifier.c mishandles bounds tracking during…
- CVE-2020-271972 PoCsTAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http://…
- CVE-2020-271991 PoCThe Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application currently has in…
- CVE-2020-272081 PoCThe flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the…
- CVE-2020-272131 PoCAn issue was discovered in Ethernut Nut/OS 5.1. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the…
- CVE-2020-272191 PoCIn all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain…
- CVE-2020-272233 PoCsIn Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple…
- CVE-2020-272241 PoCIn Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code.
- CVE-2020-272261 PoCAn exploitable SQL injection vulnerability exists in ‘quickFile.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can…
- CVE-2020-272271 PoCAn exploitable unatuhenticated command injection exists in the OpenClinic GA 5.173.3. Specially crafted web requests can cause commands to…
- CVE-2020-272281 PoCAn incorrect default permissions vulnerability exists in the installation functionality of OpenClinic GA 5.173.3. Overwriting the binary…
- CVE-2020-272291 PoCA number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The…
- CVE-2020-272301 PoCA number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The…
- CVE-2020-272311 PoCA number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The…
- CVE-2020-272321 PoCAn exploitable SQL injection vulnerability exists in ‘manageServiceStocks.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP…
- CVE-2020-272331 PoCAn exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the supplierUID parameter. An…
- CVE-2020-272341 PoCAn exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the serviceUID parameter. An…
- CVE-2020-272351 PoCAn exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the description parameter. An…
- CVE-2020-272361 PoCAn exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the compnomenclature parameter. An…
- CVE-2020-272371 PoCAn exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the The…
- CVE-2020-272381 PoCAn exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the…
- CVE-2020-272391 PoCAn exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The assetStatus parameter in the…
- CVE-2020-272401 PoCAn exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The componentStatus parameter in the…
- CVE-2020-272411 PoCAn exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The serialnumber parameter in the…
- CVE-2020-272421 PoCAn exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoLocation…
- CVE-2020-272431 PoCAn exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoService…
- CVE-2020-272441 PoCAn exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoCode…
- CVE-2020-272451 PoCAn exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoBuyer…
- CVE-2020-272461 PoCAn exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoComment…
- CVE-2020-272501 PoCIn SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014), a specially crafted document can cause the document parser to…
- CVE-2020-273012 PoCsA stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "AES_UnWRAP"…
- CVE-2020-273021 PoCA stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "memcpy" function,…
- CVE-2020-273471 PoCtmux stack buffer overflow in function input_csi_dispatch_sgr_colon
- CVE-2020-273481 PoCsnapcraft may build snaps with incorrect LD_LIBRARY_PATH
- CVE-2020-273521 PoCWhen generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result…
- CVE-2020-273581 PoCAn issue was discovered in REDCap 8.11.6 through 9.x before 10. The messenger's CSV feature (that allows users to export their…
- CVE-2020-273591 PoCA cross-site scripting (XSS) issue in REDCap 8.11.6 through 9.x before 10 allows attackers to inject arbitrary JavaScript or HTML in the…
- CVE-2020-273611 PoCAn issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within the /pme…
- CVE-2020-273681 PoCDirectory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /icons/ directories…
- CVE-2020-273731 PoCDr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to Plain text command over BLE.
- CVE-2020-273741 PoCDr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to BP Monitoring.
- CVE-2020-273751 PoCDr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Transmitting Write Requests and Chars.
- CVE-2020-273761 PoCDr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication.
- CVE-2020-273831 PoCBattle.net.exe in Battle.Net 1.27.1.12428 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated…
- CVE-2020-273841 PoCThe Gw2-64.exe in Guild Wars 2 launcher version 106916 suffers from an elevation of privileges vulnerability which can be used by an…
- CVE-2020-273851 PoCIncorrect Access Control in the FileEditor (/Admin/Views/FileEditor/) in FlexDotnetCMS before v1.5.11 allows an authenticated remote…
- CVE-2020-273862 PoCsAn unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary…
- CVE-2020-273873 PoCsAn unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the…
- CVE-2020-273971 PoCMarital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing remote attackers…
- CVE-2020-274022 PoCsThe HK1 Box S905X3 TV Box contains a vulnerability that allows a local unprivileged user to escalate to root using the /system/xbin/su…
- CVE-2020-274033 PoCsA vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group…
- CVE-2020-274061 PoCCross Site Scripting (XSS) vulnerability in DynPG 4.9.1, allows authenticated attackers to execute arbitrary code via the groupname.
- CVE-2020-274141 PoCMahavitaran android application 7.50 and prior transmit sensitive information in URL parameters. This may lead to information disclosure…
- CVE-2020-274221 PoCIn Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the…
- CVE-2020-274231 PoCAnuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack…
- CVE-2020-274611 PoCA remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote code execution…
- CVE-2020-274672 PoCsA Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php.
- CVE-2020-274812 PoCsAn unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in…
- CVE-2020-274841 PoCGarmin Forerunner 235 before 8.20 is affected by: Integer Overflow. The component is: ConnectIQ TVM. The attack vector is: To exploit the…
- CVE-2020-274882 PoCsLoxone Miniserver devices with firmware before 11.1 (aka 11.1.9.3) are unable to use an authentication method that is based on the…
- CVE-2020-275111 PoCAn issue was discovered in the stripTags and unescapeHTML components in Prototype 1.7.3 where an attacker can cause a Regular Expression…
- CVE-2020-275151 PoCA Cross Site Scripting (XSS) vulnerability in Savsoft Quiz v5.0 allows remote attackers to inject arbitrary web script or HTML via the…
- CVE-2020-275181 PoCAll versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the WindscribeService…
- CVE-2020-275231 PoCSolstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers %x; %p; %c and %s in the screen_key, display_name,…
- CVE-2020-275241 PoCOn Audi A7 MMI 2014 vehicles, the Bluetooth stack in Audi A7 MMI Multiplayer with version (N+R_CN_AU_P0395) mishandles %x and %s format…
- CVE-2020-275333 PoCsA Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into…
- CVE-2020-275391 PoCHeap overflow with full parsing of HTTP respose in Rostelecom CS-C2SHW 5.0.082.1. AgentUpdater service has a self-written HTTP parser and…
- CVE-2020-275401 PoCBash injection vulnerability and bypass of signature verification in Rostelecom CS-C2SHW 5.0.082.1. The camera reads firmware update…
- CVE-2020-275411 PoCDenial of Service vulnerability in Rostelecom CS-C2SHW 5.0.082.1. AgentGreen service has a bug in parsing broadcast discovery UDP packet.…
- CVE-2020-275421 PoCRostelecom CS-C2SHW 5.0.082.1 is affected by: Bash command injection. The camera reads configuration from QR code (including network…
- CVE-2020-275431 PoCThe restify-paginate package 0.0.5 for Node.js allows remote attackers to cause a Denial-of-Service by omitting the HTTP Host header. A…
- CVE-2020-275531 PoCIn BASETech GE-131 BT-1837836 firmware 20180921, the web-server on the system is configured with the option “DocumentRoot /etc“. This…
- CVE-2020-275541 PoCCleartext Transmission of Sensitive Information vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 exists which could leak…
- CVE-2020-275551 PoCUse of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to execute…
- CVE-2020-275561 PoCA predictable device ID in BASETech GE-131 BT-1837836 firmware 20180921 allows unauthenticated remote attackers to connect to the device.
- CVE-2020-275571 PoCUnprotected Storage of Credentials vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 allows local users to gain access to the…
- CVE-2020-275581 PoCUse of an undocumented user in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to view the video stream.
- CVE-2020-275741 PoCMaxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site request forgery (CSRF). If an authenticated user visits a malicious page,…
- CVE-2020-275752 PoCsMaxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability. The web administration contains functionality in which…
- CVE-2020-275831 PoCIBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated…
- CVE-2020-276002 PoCsHNAP1/control/SetMasterWLanSettings.php in D-Link D-Link Router DIR-846 DIR-846 A1_100.26 allows remote attackers to execute arbitrary…
- CVE-2020-276031 PoCBigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files.
- CVE-2020-276153 PoCsThe Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and…
- CVE-2020-276211 PoCThe FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific user's IP address.…
- CVE-2020-276371 PoCThe R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to server…
- CVE-2020-276521 PoCAlgorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle…
- CVE-2020-276531 PoCAlgorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to…
- CVE-2020-276581 PoCSynology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which…
- CVE-2020-276591 PoCMultiple cross-site scripting (XSS) vulnerabilities in Synology SafeAccess before 1.2.3-0234 allow remote attackers to inject arbitrary…
- CVE-2020-276601 PoCSQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL…
- CVE-2020-276661 PoCStrapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.
- CVE-2020-276871 PoCThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links…
- CVE-2020-276891 PoCThe Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains undocumented default admin credentials for the web…
- CVE-2020-276901 PoCThe Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains a buffer overflow within its web management portal.…
- CVE-2020-276911 PoCThe Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 allows XSS via URLBlocking Settings, SNMP Settings, and System…
- CVE-2020-276921 PoCThe Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains multiple CSRF vulnerabilities within its web management…
- CVE-2020-276931 PoCTrend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 stores administrative passwords using a hash that is considered…
- CVE-2020-276941 PoCTrend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 has updated a specific critical library that may vulnerable to…
- CVE-2020-277352 PoCsAn XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a crafted link, leading…
- CVE-2020-277864 PoCsA flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permissions to issue ioctl…
- CVE-2020-277871 PoCA Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input file allows…
- CVE-2020-277881 PoCAn out-of-bounds read access vulnerability was discovered in UPX in PackLinuxElf64::canPack() function of p_lx_elf.cpp file. An attacker…
- CVE-2020-277901 PoCA floating point exception issue was discovered in UPX in PackLinuxElf64::invert_pt_dynamic() function of p_lx_elf.cpp file. An attacker…
- CVE-2020-277961 PoCA heap-based buffer over-read was discovered in the invert_pt_dynamic function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.
- CVE-2020-277971 PoCAn invalid memory address reference was discovered in the elf_lookup function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.
- CVE-2020-277981 PoCAn invalid memory address reference was discovered in the adjABS function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.
- CVE-2020-277991 PoCA heap-based buffer over-read was discovered in the acc_ua_get_be32 function in miniacc.h in UPX 4.0.0 via a crafted Mach-O file.
- CVE-2020-278001 PoCA heap-based buffer over-read was discovered in the get_le32 function in bele.h in UPX 4.0.0 via a crafted Mach-O file.
- CVE-2020-278011 PoCA heap-based buffer over-read was discovered in the get_le64 function in bele.h in UPX 4.0.0 via a crafted Mach-O file.
- CVE-2020-278021 PoCAn floating point exception was discovered in the elf_lookup function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.
- CVE-2020-278141 PoCA heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an…
- CVE-2020-278151 PoCA flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes…
- CVE-2020-278241 PoCA flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply…
- CVE-2020-278281 PoCThere's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an…
- CVE-2020-278382 PoCsA flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC…
- CVE-2020-278661 PoCThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020, R6080, R6120,…
- CVE-2020-278851 PoCCross-Site Scripting (XSS) vulnerability on WSO2 API Manager 3.1.0. By exploiting a Cross-site scripting vulnerability the attacker can…
- CVE-2020-279041 PoCA logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in macOS Big…
- CVE-2020-279051 PoCA memory corruption issue was addressed with improved state management. This issue is fixed in iOS 14.2 and iPadOS 14.2, tvOS 14.2,…
- CVE-2020-279302 PoCsKEVA memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS…
- CVE-2020-279501 PoCKEVA memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security…
- CVE-2020-2795529 PoCsGit LFS 2.12.0 allows Remote Code Execution.
- CVE-2020-279561 PoCAn Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the user to conduct…
- CVE-2020-279741 PoCNeoPost Mail Accounting Software Pro 5.0.6 allows php/Commun/FUS_SCM_BlockStart.php?code= XSS.
- CVE-2020-279751 PoCosCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.
- CVE-2020-279762 PoCsosCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to…
- CVE-2020-279801 PoCGenexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to perform malicious…
- CVE-2020-279823 PoCsIceWarp 11.4.5.0 allows XSS via the language parameter.
- CVE-2020-279864 PoCsSonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI.…
- CVE-2020-279921 PoCDr.Fone 3.0.0 allows local users to gain privileges via a Trojan horse DriverInstall.exe because…
- CVE-2020-279931 PoCHrsale 2.0.0 allows download?type=files&filename=../ directory traversal to read arbitrary files.
- CVE-2020-279942 PoCsSolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal.
- CVE-2020-279961 PoCAn issue was discovered in SmartStoreNET before 4.0.1. It does not properly consider the need for a CustomModelPartAttribute decoration in…
- CVE-2020-279971 PoCAn issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) protection may lead to elevation of…