CVE-2020-35000 to CVE-2020-35999
170 CVEs with public proof-of-concept exploits.
- CVE-2020-350121 PoCEvents Manager < 5.9.8 - Admin+ SQL Injection
- CVE-2020-350371 PoCEvents Manager < 5.9.8 - Cross-Site Scripting (XSS)
- CVE-2020-351251 PoCA cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inject executable…
- CVE-2020-351261 PoCTypesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI. NOTE: the…
- CVE-2020-351312 PoCsCockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in…
- CVE-2020-351512 PoCsThe Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql…
- CVE-2020-351911 PoCThe official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the…
- CVE-2020-351991 PoCIgnite Realtime Openfire 4.6.0 has create-bookmark.jsp groupchatJID Stored XSS.
- CVE-2020-352001 PoCIgnite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS.
- CVE-2020-352011 PoCIgnite Realtime Openfire 4.6.0 has create-bookmark.jsp users Stored XSS.
- CVE-2020-352021 PoCIgnite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS.
- CVE-2020-352071 PoCAn issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. The PIN…
- CVE-2020-352081 PoCAn issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. The password…
- CVE-2020-352111 PoCAn issue in Atomix v3.1.5 allows unauthorized Atomix nodes to become the lead node in a target cluster via manipulation of the variable…
- CVE-2020-352342 PoCsThe easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an…
- CVE-2020-352401 PoCFluxBB 1.5.11 is affected by cross-site scripting (XSS in the Blog Content component. This vulnerability can allow an attacker to inject…
- CVE-2020-352413 PoCsFlatPress 1.0.3 is affected by cross-site scripting (XSS) in the Blog Content component. This vulnerability can allow an attacker to…
- CVE-2020-352421 PoCFlamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserTeamInfoInDbAndMemory.
- CVE-2020-352431 PoCFlamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserInfoInDb.
- CVE-2020-352441 PoCFlamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addGroup.
- CVE-2020-352451 PoCFlamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addUser.
- CVE-2020-352491 PoCCross Site Scripting (XSS) vulnerability in ElkarBackup 1.3.3, allows attackers to execute arbitrary code via the name parameter to the…
- CVE-2020-352521 PoCCross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registration & Login…
- CVE-2020-352613 PoCsCross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Restaurant Name field to…
- CVE-2020-352622 PoCsCross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date module and…
- CVE-2020-352631 PoCEgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code…
- CVE-2020-352701 PoCStudent Result Management System In PHP With Source Code is affected by SQL injection. An attacker can able to access of Admin Panel and…
- CVE-2020-352711 PoCEmployee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Employees,…
- CVE-2020-352721 PoCEmployee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Admin Portal in…
- CVE-2020-352731 PoCEgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain…
- CVE-2020-352741 PoCDotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges. An attacker could…
- CVE-2020-352751 PoCCoastercms v5.8.18 is affected by cross-site Scripting (XSS). A user can steal a cookie and make the user redirect to any malicious…
- CVE-2020-352761 PoCEgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin…
- CVE-2020-352841 PoCFlamingo (aka FlamingoIM) through 2020-09-29 allows ../ directory traversal because the only ostensibly unpredictable part of a…
- CVE-2020-353091 PoCBakeshop Online Ordering System in PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to inject an…
- CVE-2020-353132 PoCsA server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows…
- CVE-2020-353143 PoCsA remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote…
- CVE-2020-353271 PoCSQL injection vulnerability was discovered in Courier Management System 1.0, which can be exploited via the ref_no (POST) parameter to…
- CVE-2020-353281 PoCCourier Management System 1.0 - 'First Name' Stored XSS
- CVE-2020-353291 PoCCourier Management System 1.0 1.0 is affected by SQL Injection via 'MULTIPART street '.
- CVE-2020-353371 PoCThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which…
- CVE-2020-353382 PoCsThe Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier has a default…
- CVE-2020-353391 PoCIn 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and…
- CVE-2020-353421 PoCGNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow…
- CVE-2020-353461 PoCCXUUCMS V3 3.1 is affected by a reflected XSS vulnerability that allows remote attackers to inject arbitrary web script or HTML via the…
- CVE-2020-353471 PoCCXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add.
- CVE-2020-353491 PoCSavsoft Quiz 5 is affected by: Cross Site Scripting (XSS) via field_title (aka a title on the custom fields page).
- CVE-2020-353592 PoCsPure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit.
- CVE-2020-353621 PoCDEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow remote files to be…
- CVE-2020-353641 PoCBeijing Huorong Internet Security 5.0.55.2 allows a non-admin user to escalate privileges by injecting code into a process, and then…
- CVE-2020-353701 PoCA RCE vulnerability exists in Raysync below 3.3.3.8. An unauthenticated unauthorized attacker sending a specifically crafted request to…
- CVE-2020-353761 PoCXpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the…
- CVE-2020-353781 PoCSQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass…
- CVE-2020-353881 PoCrainrocka xinhu 2.1.9 allows remote attackers to obtain sensitive information via an index.php?a=gettotal request in which the ajaxbool…
- CVE-2020-353914 PoCsTenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a…
- CVE-2020-353952 PoCsXSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious…
- CVE-2020-353962 PoCsEGavilan Barcodes generator 1.0 is affected by: Cross Site Scripting (XSS) via the index.php. An Attacker is able to inject the XSS…
- CVE-2020-353981 PoCAn issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames…
- CVE-2020-354163 PoCsMultiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage…
- CVE-2020-354191 PoCCross Site Scripting (XSS) in Group Office CRM 6.4.196 via the SET_LANGUAGE parameter.
- CVE-2020-354271 PoCSQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands…
- CVE-2020-354301 PoCSQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to…
- CVE-2020-354372 PoCsSubrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/…
- CVE-2020-354481 PoCAn issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based…
- CVE-2020-354601 PoCcommon/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the…
- CVE-2020-354769 PoCsA remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is…
- CVE-2020-354882 PoCsThe fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon…
- CVE-2020-354893 PoCsThe contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution…
- CVE-2020-354901 PoCFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to…
- CVE-2020-354911 PoCFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to…
- CVE-2020-354981 PoCA vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to…
- CVE-2020-355301 PoCIn LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can…
- CVE-2020-355321 PoCIn LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp)…
- CVE-2020-355351 PoCIn LibRaw, there is an out-of-bounds read vulnerability within the "LibRaw::parseSonySRF()" function (libraw\src\metadata\sony.cpp) when…
- CVE-2020-355451 PoCTime-based SQL injection exists in Spotweb 1.4.9 via the query string.
- CVE-2020-355721 PoCAdminer through 4.7.8 allows XSS via the history parameter to the default URI.
- CVE-2020-355752 PoCsA password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to…
- CVE-2020-355762 PoCsA Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows…
- CVE-2020-355784 PoCsAn issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature is mishandled…
- CVE-2020-355791 PoCtindy2013 subconverter 0.6.4 has a /sub?target=%TARGET%&url=%URL%&config=%CONFIG% API endpoint that accepts an arbitrary %URL% value and…
- CVE-2020-355801 PoCA local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read…
- CVE-2020-355811 PoCA stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitrary…
- CVE-2020-355821 PoCA stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitrary…
- CVE-2020-355891 PoCThe limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows wp-admin/options-general.php?page=limit-login-attempts&tab=…
- CVE-2020-355901 PoCLimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate…
- CVE-2020-355911 PoCPi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A…
- CVE-2020-355921 PoCPi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitrary web script or…
- CVE-2020-355931 PoCBMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host.
- CVE-2020-355972 PoCsVictor CMS 1.0 is vulnerable to SQL injection via c_id parameter of admin_edit_comment.php, p_id parameter of admin_edit_post.php, u_id…
- CVE-2020-355982 PoCsACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=..%2f URI. NOTE:…
- CVE-2020-356064 PoCsArbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary…
- CVE-2020-356082 PoCsA code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A…
- CVE-2020-356091 PoCA denial-of-service vulnerability exists in the asynchronous ioctl functionality of Microsoft Azure Sphere 20.05. A sequence of specially…
- CVE-2020-356131 PoC[20201104] - Core - SQL injection in com_users list view
- CVE-2020-356161 PoC[20201107] - Core - Write ACL violation in multiple core views
- CVE-2020-356271 PoCUltimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute…
- CVE-2020-356291 PoCMultiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted…
- CVE-2020-356301 PoCMultiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted…
- CVE-2020-356311 PoCMultiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted…
- CVE-2020-356321 PoCMultiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted…
- CVE-2020-356331 PoCA code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability…
- CVE-2020-356341 PoCA code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability…
- CVE-2020-356351 PoCA code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h…
- CVE-2020-356361 PoCA code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h…
- CVE-2020-356601 PoCCross Site Scripting (XSS) in Monica before 2.19.1 via the journal page.
- CVE-2020-356653 PoCsAn unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event…
- CVE-2020-356672 PoCsJetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials.
- CVE-2020-356691 PoCAn issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request…
- CVE-2020-356821 PoCZoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).
- CVE-2020-356871 PoCPHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the…
- CVE-2020-356931 PoCOn some Samsung phones and tablets running Android through 7.1.1, it is possible for an attacker-controlled Bluetooth Low Energy (BLE)…
- CVE-2020-357001 PoCA second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNMS before 21.1.0…
- CVE-2020-357021 PoCDCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports…
- CVE-2020-357041 PoCDaybyday 2.1.0 allows stored XSS via the Title parameter to the New Lead screen.
- CVE-2020-357051 PoCDaybyday 2.1.0 allows stored XSS via the Name parameter to the New User screen.
- CVE-2020-357061 PoCDaybyday 2.1.0 allows stored XSS via the Title parameter to the New Project screen.
- CVE-2020-357071 PoCDaybyday 2.1.0 allows stored XSS via the Company Name parameter to the New Client screen.
- CVE-2020-357081 PoCphpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Administrators" page.
- CVE-2020-357101 PoCParallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submission of the login…
- CVE-2020-357133 PoCsBelkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell…
- CVE-2020-357141 PoCBelkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via…
- CVE-2020-357151 PoCBelkin LINKSYS RE6500 devices before 1.0.012.001 allow remote authenticated users to execute arbitrary commands via shell metacharacters…
- CVE-2020-357161 PoCBelkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to cause a persistent denial of service (segmentation fault) via a…
- CVE-2020-357174 PoCszonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is…
- CVE-2020-357282 PoCsFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to…
- CVE-2020-357298 PoCsKLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
- CVE-2020-357301 PoCKEVAn XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a…
- CVE-2020-357341 PoCSruu.pl in Batflat 1.3.6 allows an authenticated user to perform code injection (and consequently Remote Code Execution) via the input…
- CVE-2020-357363 PoCsGateOne 1.1 allows arbitrary file download without authentication via /downloads/.. directory traversal because os.path.join is misused.
- CVE-2020-357372 PoCsIn Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating…
- CVE-2020-357381 PoCWavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE:…
- CVE-2020-357451 PoCPHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all…
- CVE-2020-357496 PoCsDirectory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2.9.3 and earlier…
- CVE-2020-357521 PoCBaby Care System 1.0 is affected by a cross-site scripting (XSS) vulnerability in the Edit Page tab through the Post title parameter.
- CVE-2020-357542 PoCsOpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code…
- CVE-2020-357591 PoCbloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).
- CVE-2020-357601 PoCbloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files).
- CVE-2020-357611 PoCbloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code.
- CVE-2020-357621 PoCbloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files.
- CVE-2020-357741 PoCserver/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows…
- CVE-2020-357751 PoCCITSmart before 9.1.2.23 allows LDAP Injection.
- CVE-2020-357821 PoCCertain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0.48, JGS524Ev2…
- CVE-2020-358466 PoCsAgentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
- CVE-2020-358476 PoCsAgentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
- CVE-2020-358485 PoCsAgentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
- CVE-2020-358491 PoCAn issue was discovered in MantisBT before 2.24.4. An incorrect access check in bug_revision_view_page.php allows an unprivileged attacker…
- CVE-2020-358502 PoCsAn SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor…
- CVE-2020-358521 PoCChatbox is affected by cross-site scripting (XSS). An attacker has to upload any XSS payload with SVG, XML file in Chatbox. There is no…
- CVE-2020-358531 PoC4images Image Gallery Management System 1.7.11 is affected by cross-site scripting (XSS) in the Image URL. This vulnerability can result…
- CVE-2020-358541 PoCTextpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.
- CVE-2020-359301 PoCSeo Panel 4.8.0 allows stored XSS by an Authenticated User via the url parameter, as demonstrated by the seo/seopanel/websites.php URI.
- CVE-2020-359442 PoCsAn issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF,…
- CVE-2020-359452 PoCsAn issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers,…
- CVE-2020-359462 PoCsAn issue was discovered in the All in One SEO Pack plugin before 3.6.2 for WordPress. The SEO Description and Title fields are vulnerable…
- CVE-2020-359472 PoCsAn issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission…
- CVE-2020-359482 PoCsAn issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability…
- CVE-2020-359492 PoCsAn issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers…
- CVE-2020-359501 PoCAn issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).
- CVE-2020-359513 PoCsAn issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as…
- CVE-2020-359621 PoCThe sellTokenForLRC function in the vault protocol in the smart contract implementation for Loopring (LRC), an Ethereum token, lacks…
- CVE-2020-359721 PoCAn issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/member/add.html.
- CVE-2020-359731 PoCAn issue was discovered in zzcms2020. There is a XSS vulnerability that can insert and execute JS code arbitrarily via /user/manage.php.
- CVE-2020-359791 PoCAn issue was discovered in GPAC version 0.8.0 and 1.0.1. There is heap-based buffer overflow in the function gp_rtp_builder_do_avc() in…
- CVE-2020-359801 PoCAn issue was discovered in GPAC version 0.8.0 and 1.0.1. There is a use-after-free in the function gf_isom_box_del() in…
- CVE-2020-359811 PoCAn issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function SetupWriters() in…
- CVE-2020-359821 PoCAn issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function…
- CVE-2020-359841 PoCA stored cross site scripting (XSS) vulnerability in the 'Users Alerts' feature of Rukovoditel 2.7.2 allows authenticated attackers to…
- CVE-2020-359851 PoCA stored cross site scripting (XSS) vulnerability in the 'Global Lists" feature of Rukovoditel 2.7.2 allows authenticated attackers to…
- CVE-2020-359861 PoCA stored cross site scripting (XSS) vulnerability in the 'Users Access Groups' feature of Rukovoditel 2.7.2 allows authenticated attackers…
- CVE-2020-359871 PoCA stored cross site scripting (XSS) vulnerability in the 'Entities List' feature of Rukovoditel 2.7.2 allows authenticated attackers to…