CVE-2020-36000 to CVE-2020-36999
260 CVEs with public proof-of-concept exploits.
- CVE-2020-360021 PoCSeat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id parameter where attackers can obtain sensitive…
- CVE-2020-360091 PoCOBottle 2.0 in \c\g.php contains an arbitrary file download vulnerability.
- CVE-2020-360111 PoCA cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject…
- CVE-2020-360121 PoCStored XSS vulnerability in BDTASK Multi-Store Inventory Management System 1.0 allows a local admin to inject arbitrary code via the…
- CVE-2020-360231 PoCAn issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted…
- CVE-2020-360241 PoCAn issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted…
- CVE-2020-360371 PoCAn issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the…
- CVE-2020-360481 PoCEngine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling…
- CVE-2020-360491 PoCsocket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a…
- CVE-2020-360621 PoCDairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to…
- CVE-2020-360651 PoCCross Site Request Forgery (CSRF) vulnerability in FlyCms 1.0 allows attackers to add arbitrary administrator accounts via…
- CVE-2020-360661 PoCGJSON <1.6.5 allows attackers to cause a denial of service (remote) via crafted JSON.
- CVE-2020-360793 PoCsZenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to…
- CVE-2020-360841 PoCSQL Injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows remote attackers to inject sql query in…
- CVE-2020-361092 PoCsASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function of the httpd…
- CVE-2020-361122 PoCsCSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in…
- CVE-2020-361151 PoCStored Cross Site Scripting (XSS) vulnerability in EGavilan Media CRUD Operation with PHP, MySQL, Bootstrap, and Dompdf via First Name or…
- CVE-2020-361201 PoCBuffer Overflow in the "sixel_encoder_encode_bytes" function of Libsixel v1.8.6 allows attackers to cause a Denial of Service (DoS).
- CVE-2020-361541 PoCThe Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMDRIVE%\Pearson VUE"…
- CVE-2020-361552 PoCsAn issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta.…
- CVE-2020-361561 PoCAn issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile…
- CVE-2020-361571 PoCAn issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User…
- CVE-2020-361793 PoCsFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to…
- CVE-2020-361802 PoCsFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to…
- CVE-2020-361811 PoCFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to…
- CVE-2020-361821 PoCFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to…
- CVE-2020-361831 PoCFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to…
- CVE-2020-361842 PoCsFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to…
- CVE-2020-361851 PoCFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to…
- CVE-2020-361861 PoCFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to…
- CVE-2020-361871 PoCFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to…
- CVE-2020-361882 PoCsFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to…
- CVE-2020-361891 PoCFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to…
- CVE-2020-362411 PoCautoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal…
- CVE-2020-362872 PoCsThe dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5,…
- CVE-2020-362891 PoCAffected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure…
- CVE-2020-363141 PoCfr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during…
- CVE-2020-363151 PoCIn RELIC before 2020-08-01, RSA PKCS#1 v1.5 signature forgery can occur because certain checks of the padding (and of the first two bytes)…
- CVE-2020-363161 PoCIn RELIC before 2021-04-03, there is a buffer overflow in PKCS#1 v1.5 signature verification because garbage bytes can be present.
- CVE-2020-363171 PoCIn the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem. It allows creation of a non-UTF-8…
- CVE-2020-363332 PoCsthemegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.
- CVE-2020-363341 PoCthemegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.
- CVE-2020-363651 PoCSmartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and…
- CVE-2020-363671 PoCStack overflow vulnerability in parse_block Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted…
- CVE-2020-363681 PoCStack overflow vulnerability in parse_statement Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a…
- CVE-2020-363691 PoCStack overflow vulnerability in parse_statement_list Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a…
- CVE-2020-363701 PoCStack overflow vulnerability in parse_unary Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted…
- CVE-2020-363711 PoCStack overflow vulnerability in parse_mul_div_rem Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a…
- CVE-2020-363721 PoCStack overflow vulnerability in parse_plus_minus Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a…
- CVE-2020-363731 PoCStack overflow vulnerability in parse_shifts Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted…
- CVE-2020-363741 PoCStack overflow vulnerability in parse_comparison Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a…
- CVE-2020-363751 PoCStack overflow vulnerability in parse_equality Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a…
- CVE-2020-363761 PoCAn issue was discovered in the list function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath…
- CVE-2020-363771 PoCAn issue was discovered in the dump function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath…
- CVE-2020-363781 PoCAn issue was discovered in the packageCmd function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath…
- CVE-2020-363791 PoCAn issue was discovered in the remove function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath…
- CVE-2020-363801 PoCAn issue was discovered in the crunch function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath…
- CVE-2020-363811 PoCAn issue was discovered in the singleCrunch function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath…
- CVE-2020-364201 PoCPolipo through 1.1.1, when NDEBUG is omitted, allows denial of service via a reachable assertion during parsing of a malformed Range…
- CVE-2020-364611 PoCAn issue was discovered in the noise_search crate through 2020-12-10 for Rust. There are unconditional implementations of Send and Sync…
- CVE-2020-364621 PoCAn issue was discovered in the syncpool crate before 0.1.6 for Rust. There is an unconditional implementation of Send for Bucket2.
- CVE-2020-364641 PoCAn issue was discovered in the heapless crate before 0.6.1 for Rust. The IntoIter Clone implementation clones an entire underlying Vec…
- CVE-2020-364851 PoCPortable Ltd Playable v9.18 was discovered to contain an arbitrary file upload vulnerability in the filename parameter of the upload…
- CVE-2020-364861 PoCSwift File Transfer Mobile v1.1.2 and below was discovered to contain a cross-site scripting (XSS) vulnerability via the 'path' parameter…
- CVE-2020-364881 PoCAn issue in the FTP server of Sky File v2.1.0 allows attackers to perform directory traversal via `/null//` path commands.
- CVE-2020-364891 PoCDropouts Technologies LLP Air Share v1.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the devicename parameter.…
- CVE-2020-364901 PoCDedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via…
- CVE-2020-364911 PoCDedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tags_main.php via the…
- CVE-2020-364921 PoCDedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component select_media.php via the…
- CVE-2020-364931 PoCDedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component media_main.php via the…
- CVE-2020-364941 PoCDedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component mychannel_edit.php via the…
- CVE-2020-364951 PoCDedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via…
- CVE-2020-364961 PoCDedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component sys_admin_user_edit.php…
- CVE-2020-364971 PoCDedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtml_homepage.php via…
- CVE-2020-364981 PoCMacrob7 Macs Framework Content Management System - 1.14f contains a cross-site scripting (XSS) vulnerability in the account reset…
- CVE-2020-364991 PoCTAO Open Source Assessment Platform v3.3.0 RC02 was discovered to contain a cross-site scripting (XSS) vulnerability in the content…
- CVE-2020-365011 PoCMultiple cross-site scripting (XSS) vulnerabilities in the Support module of SugarCRM v6.5.18 allows attackers to execute arbitrary web…
- CVE-2020-365021 PoCSwift File Transfer Mobile v1.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the devicename parameter which…
- CVE-2020-365031 PoCConnections Business Directory < 9.7 - Admin+ CSV Injection
- CVE-2020-365041 PoCWP-Pro-Quiz <= 0.37 - Arbitrary Quiz Deletion via CSRF
- CVE-2020-365051 PoCDelete All Comments Easily <= 1.3 - All Comments Deletion via CSRF
- CVE-2020-365102 PoCs15Zine < 3.3.0 - Reflected Cross-Site Scripting
- CVE-2020-365181 PoCjackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
- CVE-2020-365191 PoCMimecast Email Security before 2020-01-10 allows any admin to spoof any domain, and pass DMARC alignment via SPF. This occurs through…
- CVE-2020-365231 PoCPlantUML Database Information Macro cross site scripting
- CVE-2020-365241 PoCRefined Toolkit UI-Image/UI-Button cross site scripting
- CVE-2020-365251 PoCLinking New Windows Macro cross site scripting
- CVE-2020-365261 PoCCountdown Timer Macro cross site scripting
- CVE-2020-365271 PoCServer Status HTTP Status/SMTP Status cross site scripting
- CVE-2020-365281 PoCPlatinum Mobile MobileHandler.ashx access control
- CVE-2020-365291 PoCSevOne Network Management System Traceroute traceroute.php command injection
- CVE-2020-365301 PoCSevOne Network Management System Alert Summary sql injection
- CVE-2020-365341 PoCeasyii CMS out cross-site request forgery
- CVE-2020-365411 PoCDemokratian genera_select.php sql injection
- CVE-2020-365421 PoCDemokratian install3.php privileges management
- CVE-2020-365431 PoCSialWeb CMS about.php sql injection
- CVE-2020-365441 PoCSialWeb CMS Search cross site scriting
- CVE-2020-365503 PoCsCross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Table Name field to…
- CVE-2020-365513 PoCsCross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Item Name field to…
- CVE-2020-365523 PoCsCross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Made field to…
- CVE-2020-365533 PoCsCross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Area(food_type) field to…
- CVE-2020-365581 PoCA race condition in the Linux kernel before 5.5.7 involving VT_RESIZEX could lead to a NULL pointer dereference and general protection…
- CVE-2020-365601 PoCPath traversal in github.com/artdarek/go-unzip
- CVE-2020-365611 PoCPath traversal in github.com/yi-ge/unzip
- CVE-2020-365651 PoCDirectory traversal on Windows in github.com/labstack/echo/v4
- CVE-2020-366034 PoCsThe HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function…
- CVE-2020-366071 PoCCross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html…
- CVE-2020-366091 PoCannyshow DuxCMS Article edit cross site scripting
- CVE-2020-366101 PoCannyshow DuxCMS cross-site request forgery
- CVE-2020-366291 PoCSimbCo httpster server.coffee fs.realpathSync path traversal
- CVE-2020-366511 PoCyoungerheart nodeserver nodeserver.js path traversal
- CVE-2020-366561 PoCSpectra < 1.15.0 - Contributor+ Stored Cross-Side Scripting
- CVE-2020-366661 PoCMultiple e-plugins - Subscriber+ Privilege Escalation
- CVE-2020-367051 PoCAdning Advertising <= 1.5.5 - Arbitrary File Upload
- CVE-2020-367082 PoCsEpsilon Framework Themes (Various Versions) - Function Injection
- CVE-2020-367231 PoCListingPro - WordPress Directory & Listing Theme < 2.6.1 - Sensitive Information Disclosure
- CVE-2020-367281 PoCAdning Advertising <= 1.5.5 - Unauthenticated Arbitrary File Deletion via Path Traversal
- CVE-2020-367301 PoCCMP <= 3.8.1 - Missing Authorization
- CVE-2020-367311 PoCFlexible Checkout Fields for WooCommerce <= 2.3.1 - Unauthenticated Arbitrary Plugin Settings Update
- CVE-2020-367531 PoCHueman <= 3.6.3 - Cross-Site Request Forgery Bypass
- CVE-2020-367551 PoCCustomizr <= 4.3.0 - Cross-Site Request Forgery Bypass
- CVE-2020-367605 PoCsOcean Extra <=1.6.5 - Cross-Site Request Forgery Bypass
- CVE-2020-367615 PoCsTop 10 <= 2.9.4 - Cross-Site Request Forgery Bypass
- CVE-2020-367631 PoCCross Site Scripting (XSS) vulnerability in DuxCMS 2.1 allows remote attackers to run arbitrary code via the content, time, copyfrom…
- CVE-2020-367681 PoCrl-institut NESP2 database.py sql injection
- CVE-2020-367712 PoCsCloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local…
- CVE-2020-367722 PoCsCloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allows local users to…
- CVE-2020-368301 PoCnescalante urlregex Backtracking index.js redos
- CVE-2020-368361 PoCWP Fastest Cache <= 0.9.0.2 - Authenticated (Subscriber+) Arbitrary File Deletion
- CVE-2020-368421 PoCMigration, Backup, Staging – WPvivid <= 0.9.35 - Authenticated (Subscriber+) Arbitrary File Upload
- CVE-2020-368474 PoCsSimple File List < 4.2.3 - Remote Code Execution
- CVE-2020-368482 PoCsTotal Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Download
- CVE-2020-368491 PoCAIT CSV import/export <= 3.0.3 - Unauthenticated Arbitrary File Upload
- CVE-2020-368551 PoCDCMTK dcmqrscp parseQuota stack-based overflow
- CVE-2020-368712 PoCsESCAM QD-900 Unauthenticated Configuration Disclosure
- CVE-2020-368724 PoCsBACnet Test Server 1.01 Malformed BVLC Length DoS
- CVE-2020-368731 PoCAstak CM-818T3 Unauthenticated Configuration Disclosure
- CVE-2020-368742 PoCsACE SECURITY WIP-90113 Unauthenticated Configuration Disclosure
- CVE-2020-368751 PoCAccessAlly < 3.3.2 Unauthenticated Arbitrary PHP Code Execution
- CVE-2020-368761 PoCReQuest Serious Play F3 Media Server <= 7.0.3 Debug Log Disclosure2020
- CVE-2020-368771 PoCReQuest Serious Play F3 Media Server <= 7.0.3 code execution
- CVE-2020-368781 PoCReQuest Serious Play F3 Media Player <= 3.0.0 Directory Traversal File Disclosure
- CVE-2020-368791 PoCFlexsense DiskBoss Service Unquoted Service Path Vulnerability
- CVE-2020-368801 PoCFlexsense DiskBoss 'Reports and Data Directory' Buffer Overflow
- CVE-2020-368811 PoCFlexsense DiskBoss 'Add Input Directory' Buffer Overflow
- CVE-2020-368821 PoCFlexsense DiskBoss Application Crash Denial of Service
- CVE-2020-368831 PoCSpinetiX Fusion Digital Signage 3.4.8 Authenticated Path Traversal via File Operations
- CVE-2020-368842 PoCsBrightSign Digital Signage Diagnostic Web Server 8.2.26 Unauthenticated SSRF
- CVE-2020-368851 PoCSony IPELA Network Camera 1.82.01 Remote Stack Buffer Overflow via ftpclient.cgi
- CVE-2020-368861 PoCSpinetiX Fusion Digital Signage 3.4.8 Cross-Site Request Forgery via User Creation
- CVE-2020-368871 PoCSpinetiX Fusion Digital Signage 3.4.8 Unauthenticated Database Backup Disclosure
- CVE-2020-368881 PoCSpinetiX Fusion Digital Signage 3.4.8 Username Enumeration via Login Script
- CVE-2020-368921 PoCEibiz i-Media Server Digital Signage 3.8.0 Unauthenticated Privilege Escalation
- CVE-2020-368931 PoCEibiz i-Media Server Digital Signage 3.8.0 Directory Traversal Vulnerability
- CVE-2020-368941 PoCEibiz i-Media Server Digital Signage 3.8.0 Unauthenticated User Creation Vulnerability
- CVE-2020-368951 PoCEIBIZ i-Media Server Digital Signage 3.8.0 Unauthenticated Configuration Disclosure
- CVE-2020-368961 PoCQiHang Media Web Digital Signage 3.0.9 Cleartext Credentials Disclosure
- CVE-2020-368971 PoCQiHang Media Web Digital Signage 3.0.9 Unauthenticated Remote Code Execution
- CVE-2020-368981 PoCQiHang Media Web Digital Signage 3.0.9 Unauthenticated Arbitrary File Deletion
- CVE-2020-368991 PoCQiHang Media Web Digital Signage 3.0.9 Unauthenticated Arbitrary File Disclosure
- CVE-2020-369001 PoCAll-Dynamics Digital Signage System 2.0.2 Cross-Site Request Forgery via User Management
- CVE-2020-369011 PoCUBICOD Medivision Digital Signage 1.5.1 Cross-Site Request Forgery via User Management
- CVE-2020-369021 PoCUBICOD Medivision Digital Signage 1.5.1 Authorization Bypass via User Privileges
- CVE-2020-369031 PoCSelea CarPlateServer 4.0.1.6 Local Privilege Escalation via Unquoted Service Path
- CVE-2020-369041 PoCSelea CarPlateServer 4.0.1.6 Remote Program Execution via Configuration Endpoint
- CVE-2020-369053 PoCsFIBARO System Home Center 5.021 Remote File Inclusion via Proxy API
- CVE-2020-369062 PoCsP5 FNIP-8x16A FNIP-4xSH 1.0.20 Cross-Site Request Forgery via User Management
- CVE-2020-369072 PoCsExtreme Networks Aerohive HiveOS <=11.x 11.x Unauthenticated Remote Denial of Service
- CVE-2020-369082 PoCsSecure Computing SnapGear Management Console SG560 3.1.5 Cross-Site Request Forgery via Admin Users
- CVE-2020-369092 PoCsSecure Computing SnapGear Management Console SG560 3.1.5 Arbitrary File Read/Write
- CVE-2020-369103 PoCsCayin Signage Media Player 3.0 Authenticated Remote Command Injection via NTP Parameter
- CVE-2020-369113 PoCsCovenant 0.5 - Remote Code Execution (RCE)
- CVE-2020-369121 PoCPlexus anblick Digital Signage Management 3.1.13 Open Redirect via Pagina Parameter
- CVE-2020-369131 PoCAll-Dynamics Software enlogic:show 2.0.2 Session Fixation Authentication Bypass
- CVE-2020-369141 PoCQiHang Media Web Digital Signage 3.0.9 Cookie Authentication Credentials Disclosure
- CVE-2020-369152 PoCsAdtec Digital SignEdje Digital Signage Player v2.08.28 Default Credentials
- CVE-2020-369162 PoCsTDM Digital Signage PC Player 4.1.0.4 Privilege Escalation via Insecure Permissions
- CVE-2020-369171 PoCiDS6 DSSPro Digital Signage System 6.2 Cleartext Password Disclosure via Cookie
- CVE-2020-369183 PoCsiDS6 DSSPro Digital Signage System 6.2 Cross-Site Request Forgery via User Management
- CVE-2020-369191 PoCWPForms 1.7.8 - Cross-Site Scripting (XSS)
- CVE-2020-369203 PoCsiDS6 DSSPro Digital Signage System 6.2 Privilege Escalation via Access Control
- CVE-2020-369211 PoCRED-V Super Digital Signage System 5.1.1 Log Information Disclosure Vulnerability
- CVE-2020-369223 PoCsSony BRAVIA Digital Signage 1.7.8 Unauthenticated System API Information Disclosure
- CVE-2020-369231 PoCSony BRAVIA Digital Signage 1.7.8 Client-Side Protection Bypass via IDOR
- CVE-2020-369243 PoCsSony BRAVIA Digital Signage 1.7.8 Unauthenticated Remote File Inclusion
- CVE-2020-369253 PoCsArteco Web Client DVR/NVR Session ID Brute Force Authentication Bypass
- CVE-2020-369261 PoCSmarterTools SmarterTrack 7922 -Information Disclosure
- CVE-2020-369271 PoCDiskPulse 13.6.14 - Unquoted Service Path
- CVE-2020-369281 PoCBrother BRAgent 1.38 - 'WBA_Agent_Client' Unquoted Service Path
- CVE-2020-369291 PoCBrother BRPrint Auditor 3.0.7 - 'Multiple' Unquoted Service Path
- CVE-2020-369301 PoCSysGauge 7.9.18 - ' SysGauge Server' Unquoted Service Path
- CVE-2020-369311 PoCClick2Magic 1.1.5 - Stored Cross-Site Scripting
- CVE-2020-369321 PoCSeacms 11.1 - 'checkuser' Stored XSS
- CVE-2020-369331 PoCIPTInstaller 4.0.9 - 'PassThru Service' Unquoted Service Path
- CVE-2020-369341 PoCDeep Instinct Windows Agent 1.2.24.0 - 'DeepNetworkService' Unquoted Service Path
- CVE-2020-369351 PoCKMSpico 17.1.0.0 - 'Service KMSELDI' Unquoted Service Path
- CVE-2020-369361 PoCMagic Mouse 2 utilities 2.20 - 'magicmouse2service' Unquoted Service Path
- CVE-2020-369371 PoCMEMU PLAY 3.7.0 - 'MEmusvc' Unquoted Service Path
- CVE-2020-369381 PoCWinAVR Version 20100110 - Insecure Folder Permissions
- CVE-2020-369392 PoCsCassandra Web 0.5.0 - Remote File Read
- CVE-2020-369401 PoCEasy CD & DVD Cover Creator 4.13 - Denial of Service
- CVE-2020-369411 PoCKnockpy 4.1.1 - CSV Injection
- CVE-2020-369421 PoCVictor CMS 1.0 - File Upload To RCE
- CVE-2020-369431 PoCaSc TimeTables 2021.6.2 - Denial of Service
- CVE-2020-369441 PoCILIAS Learning Management System 4.3 - SSRF
- CVE-2020-369451 PoCWebDamn User Registration & Login System with User Panel - SQLi Auth Bypass
- CVE-2020-369461 PoCSyncBreeze 10.0.28 - 'login' Denial of Service
- CVE-2020-369471 PoCLibreNMS 1.46 - MAC Accounting Graph Authenticated SQL Injection
- CVE-2020-369482 PoCsVestaCP 0.9.8-26 - 'LoginAs' Insufficient Session Validation
- CVE-2020-369491 PoCTapinRadio 2.13.7 - Denial of Service
- CVE-2020-369501 PoCLaravel Nova 3.7.0 - 'range' DoS
- CVE-2020-369511 PoCPhpscript-sgh 0.1.0 - Time Based Blind SQL Injection
- CVE-2020-369521 PoCIObit Uninstaller 10 Pro - Unquoted Service Path
- CVE-2020-369531 PoCMiniTool ShadowMaker 3.2 - 'MTAgentService' Unquoted Service Path
- CVE-2020-369541 PoCXeroneit Library Management System 3.1 - "Add Book Category " Stored XSS
- CVE-2020-369551 PoCGrav CMS 1.6.30 Admin Plugin 1.9.18 - 'Page Title' Persistent Cross-Site Scripting
- CVE-2020-369561 PoCOpenfire 4.6.0 - 'path' Stored XSS
- CVE-2020-369571 PoCPDF Complete 3.5.310.2002 - 'pdfsvc.exe' Unquoted Service Path
- CVE-2020-369581 PoCKite 1.2020.1119.0 - 'KiteService' Unquoted Service Path
- CVE-2020-369591 PoCIDT PC Audio 1.0.6499.0 - 'STacSV' Unquoted Service Path
- CVE-2020-369601 PoCForma LMS 2.3 - 'First & Last Name' Stored Cross-Site Scripting
- CVE-2020-369611 PoC10-Strike Network Inventory Explorer 8.65 - Buffer Overflow (SEH)
- CVE-2020-369621 PoCTendenci 12.3.1 - CSV/ Formula Injection
- CVE-2020-369631 PoCIntelbras Router RF 301K 1.1.2 - Authentication Bypass
- CVE-2020-369641 PoCYATinyWinFTP - Denial of Service
- CVE-2020-369651 PoCdocPrint Pro 8.0 - 'Add URL' Buffer Overflow (SEH Egghunter)
- CVE-2020-369661 PoCDolibarr 11.0.3 - 'ldap.php' - Persistent Cross-Site Scripting
- CVE-2020-369671 PoCZortam Mp3 Media Studio 27.60 - Remote Code Execution (SEH)
- CVE-2020-369681 PoCM/Monit 3.7.4 - Password Disclosure
- CVE-2020-369691 PoCM/Monit 3.7.4 - Privilege Escalation
- CVE-2020-369701 PoCPMB 5.6 - 'chemin' Local File Disclosure
- CVE-2020-369711 PoCNidesoft 3GP Video Converter 2.6.18 - Local Stack Buffer Overflow
- CVE-2020-369721 PoCSmartBlog 2.0.1 - 'id_post' Blind SQL injection
- CVE-2020-369731 PoCPDW File Browser 1.3 - Remote Code Execution
- CVE-2020-369741 PoCRealtek Andrea RT Filters 1.0.64.7 - 'AERTSr64.EXE' Unquoted Service Path
- CVE-2020-369751 PoCEPSON Status Monitor 3 'EPSON_PM_RPCV4_06' - Unquoted Service Path
- CVE-2020-369761 PoCGlobal Registration Service 1.0.0.3 - 'GREGsvc.exe' Unquoted Service Path
- CVE-2020-369771 PoCWondershare Driver Install Service help 10.7.1.321 - 'ElevationService' Unquote Service Path
- CVE-2020-369781 PoCFroxlor Froxlor Server Management Panel 0.10.16 - Persistent Cross-Site Scripting
- CVE-2020-369791 PoCAtheros Coex Service Application 8.0.0.255 -'ZAtheros Bt&Wlan Coex Agent' Unquoted Service Path
- CVE-2020-369801 PoCSAntivirus IC 10.0.21.61 - 'SAntivirusIC' Unquoted Service Path
- CVE-2020-369812 PoCsMotorola Device Manager 2.4.5 - 'ForwardDaemon.exe ' Unquoted Service Path
- CVE-2020-369821 PoCMotorola Device Manager 2.5.4 - 'MotoHelperService.exe' Unquoted Service Path
- CVE-2020-369831 PoCQuick 'n Easy FTP Service 3.2 - Unquoted Service Path
- CVE-2020-369841 PoCEPSON 1.124 - 'seksmdb.exe' Unquoted Service Path
- CVE-2020-369851 PoCIP Watcher v3.0.0.30 - 'PACService.exe' Unquoted Service Path
- CVE-2020-369861 PoCPrey 1.9.6 - "CronService" Unquoted Service Path
- CVE-2020-369871 PoCProgram Access Controller v1.2.0.0 - 'PACService.exe' Unquoted Service Path
- CVE-2020-369881 PoCPDW File Browser <= v1.3 - Cross-Site Scripting (XSS)
- CVE-2020-369891 PoCForensiTAppxService 2.2.0.4 - 'ForensiTAppxService.exe' Unquoted Service Path
- CVE-2020-369901 PoCInput Director 1.4.3 - 'Input Director' Unquoted Service Path
- CVE-2020-369911 PoCShareMouse 5.0.43 - 'ShareMouse Service' Unquoted Service Path
- CVE-2020-369921 PoCNord VPN-6.31.13.0 - 'nordvpn-service' Unquoted Service Path
- CVE-2020-369931 PoCLimeSurvey <= 4.3.10 - 'Survey Menu' Persistent Cross-Site Scripting
- CVE-2020-369941 PoCQlikView 12.50.20000.0 - 'FTP Server Address' Denial of Service
- CVE-2020-369951 PoCMocha Telnet Lite for iOS 4.2 - 'User' Denial of Service
- CVE-2020-369961 PoCPHPFusion 9.03.50 - Persistent Cross-Site Scripting
- CVE-2020-369972 PoCsBacklinkSpeed 2.4 - Buffer Overflow PoC (SEH)
- CVE-2020-369981 PoCforma.lms The E-Learning Suite 2.3.0.2 - Persistent Cross-Site Scripting
- CVE-2020-369991 PoCelaniin CMS 1.0 - Authentication Bypass