CVE-2020-5000 to CVE-2020-5999
120 CVEs with public proof-of-concept exploits.
- CVE-2020-50141 PoCIBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary code on the system…
- CVE-2020-51421 PoCA stored cross-site scripting (XSS) vulnerability exists in the SonicOS SSLVPN web interface. A remote unauthenticated attacker is able to…
- CVE-2020-51472 PoCsSonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated…
- CVE-2020-51791 PoCComtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the…
- CVE-2020-51832 PoCsFTPGetter Professional 5.97.0.223 is vulnerable to a memory corruption bug when a user sends a specially crafted string to the…
- CVE-2020-51861 PoCDNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).
- CVE-2020-51871 PoCDNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).
- CVE-2020-51881 PoCDNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
- CVE-2020-51912 PoCsPHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.
- CVE-2020-51922 PoCsPHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are…
- CVE-2020-51931 PoCPHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata or…
- CVE-2020-52022 PoCsapt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The…
- CVE-2020-52232 PoCsPersistent XSS vulnerability in filename of attached file in PrivateBin
- CVE-2020-52361 PoCCatastrophic backtracking in regex allows Denial of Service in Waitress
- CVE-2020-52371 PoCRelative Path Traversal in oneup/uploader-bundle
- CVE-2020-52451 PoCRemote Code Execution (RCE) vulnerability in dropwizard-validation
- CVE-2020-52483 PoCsPublic GLPIKEY can be used to decrypt any data in GLPI
- CVE-2020-52501 PoCPossible information disclosure in PrestaShop
- CVE-2020-52511 PoCInformation disclosure in parse-server
- CVE-2020-52541 PoCNetHack hilite_status parsing privilege escalation
- CVE-2020-52582 PoCsPrototype pollution in dojo
- CVE-2020-52603 PoCsmalicious URLs may cause Git to present stored credentials to the wrong server
- CVE-2020-52843 PoCsDirectory Traversal in Next.js versions below 9.3.2
- CVE-2020-52953 PoCsLocal File read vulnerability in OctoberCMS
- CVE-2020-52962 PoCsArbitrary File Deletion vulnerability in OctoberCMS
- CVE-2020-52972 PoCsUpload whitelisted files to any directory in OctoberCMS
- CVE-2020-52982 PoCsReflected XSS when importing CSV in OctoberCMS
- CVE-2020-53051 PoCCodoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen.
- CVE-2020-53062 PoCsCodoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content.
- CVE-2020-53072 PoCsPHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php,…
- CVE-2020-53081 PoCPHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to XSS, as demonstrated by the category and CategoryCode parameters in…
- CVE-2020-53303 PoCsDell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22 and older and Dell…
- CVE-2020-53778 PoCsDell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. An unauthenticated…
- CVE-2020-53931 PoCIn Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS.
- CVE-2020-53982 PoCsRFD Attack via "Content-Disposition" Header Sourced from Request Input by Spring MVC or Spring WebFlux Application
- CVE-2020-54054 PoCsDirectory Traversal with spring-cloud-config-server
- CVE-2020-54105 PoCsKEVDirectory Traversal with spring-cloud-config-server
- CVE-2020-54121 PoCHystrix Dashboard Proxy In spring-cloud-netflix-hystrix-dashboard
- CVE-2020-54211 PoCRFD Protection Bypass via jsessionid
- CVE-2020-54971 PoCThe OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being included in the page…
- CVE-2020-54991 PoCBaidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two global IDs are the…
- CVE-2020-55044 PoCsIn phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL…
- CVE-2020-55051 PoCFreelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with…
- CVE-2020-55092 PoCsPHPGurukul Car Rental Project v1.0 allows Remote Code Execution via an executable file in an upload of a new profile image.
- CVE-2020-55102 PoCsPHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file.
- CVE-2020-55111 PoCPHPGurukul Small CRM v2.0 was found vulnerable to authentication bypass via SQL injection when logging into the administrator login page.
- CVE-2020-55131 PoCGila CMS 1.11.8 allows /cm/delete?t=../ Directory Traversal.
- CVE-2020-55141 PoCGila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI.
- CVE-2020-55156 PoCsGila CMS 1.11.8 allows /admin/sql?query= SQL Injection.
- CVE-2020-57201 PoCMikroTik WinBox before 3.21 is vulnerable to a path traversal vulnerability that allows creation of arbitrary files wherevere WinBox has…
- CVE-2020-57226 PoCsKEVThe HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An…
- CVE-2020-57231 PoCThe UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve…
- CVE-2020-57241 PoCThe Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote…
- CVE-2020-57251 PoCThe Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote…
- CVE-2020-57262 PoCsThe Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote…
- CVE-2020-57271 PoCAuthentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated attacker to pair a…
- CVE-2020-57341 PoCClassic buffer overflow in SolarWinds Dameware allows a remote, unauthenticated attacker to cause a denial of service by sending a large…
- CVE-2020-57352 PoCsKEVAmcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this…
- CVE-2020-57381 PoCGrandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a…
- CVE-2020-57391 PoCGrandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an…
- CVE-2020-57401 PoCImproper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with…
- CVE-2020-57413 PoCsKEVDeserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.
- CVE-2020-57421 PoCImproper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests.
- CVE-2020-57431 PoCImproper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they…
- CVE-2020-57441 PoCRelative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.
- CVE-2020-57451 PoCCross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users…
- CVE-2020-57461 PoCInsufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS)…
- CVE-2020-57471 PoCInsufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS)…
- CVE-2020-57481 PoCInsufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting…
- CVE-2020-57491 PoCInsufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS)…
- CVE-2020-57501 PoCInsufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting…
- CVE-2020-57511 PoCInsufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS)…
- CVE-2020-57528 PoCsRelative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating…
- CVE-2020-57601 PoCGrandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Unauthenticated…
- CVE-2020-57611 PoCGrandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in the TR-069…
- CVE-2020-57621 PoCGrandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-069 service. An…
- CVE-2020-57631 PoCGrandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can…
- CVE-2020-57641 PoCMX Player Android App versions prior to v1.24.5, are vulnerable to a directory traversal vulnerability when user is using the MX Transfer…
- CVE-2020-57662 PoCsImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3…
- CVE-2020-57671 PoCCross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged…
- CVE-2020-57681 PoCImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & Newsletters Plugin for…
- CVE-2020-57691 PoCInsufficient output sanitization in Teltonika firmware TRB2_R_00.02.02 allows a remote, authenticated attacker to conduct persistent…
- CVE-2020-57701 PoCCross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by…
- CVE-2020-57711 PoCImproper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by…
- CVE-2020-57721 PoCImproper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by…
- CVE-2020-57731 PoCImproper Access Control in Teltonika firmware TRB2_R_00.02.04.01 allows a low privileged user to perform unauthorized write operations.
- CVE-2020-57741 PoCNessus versions 8.11.0 and earlier were found to maintain sessions longer than the permitted period in certain scenarios. The lack of…
- CVE-2020-57752 PoCsServer-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform…
- CVE-2020-57761 PoCCurrently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is possible in the event…
- CVE-2020-57771 PoCMAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in the event there is…
- CVE-2020-57801 PoCMissing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows…
- CVE-2020-57811 PoCIn IgniteNet HeliOS GLinq v2.2.1 r2961, the langSelection parameter is stored in the luci configuration file (/etc/config/luci) by the…
- CVE-2020-57821 PoCIn IgniteNet HeliOS GLinq v2.2.1 r2961, if a user logs in and sets the ‘wan_type’ parameter, the wan interface for the device will become…
- CVE-2020-57831 PoCIn IgniteNet HeliOS GLinq v2.2.1 r2961, the login functionality does not contain any CSRF protection mechanisms.
- CVE-2020-57841 PoCServer-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the application to perform HTTP…
- CVE-2020-57851 PoCInsufficient output sanitization in Teltonika firmware TRB2_R_00.02.04.3 allows an unauthenticated attacker to conduct reflected…
- CVE-2020-57861 PoCCross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive application actions by…
- CVE-2020-57871 PoCRelative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk…
- CVE-2020-57881 PoCRelative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk…
- CVE-2020-57891 PoCRelative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to read the contents of arbitrary…
- CVE-2020-57901 PoCCross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate…
- CVE-2020-57915 PoCsImproper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute…
- CVE-2020-57923 PoCsImproper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to…
- CVE-2020-57951 PoCUNIX Symbolic Link (Symlink) Following in TP-Link Archer A7(US)_V5_200721 allows an authenticated admin user, with physical access and…
- CVE-2020-57961 PoCImproper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of…
- CVE-2020-57971 PoCUNIX Symbolic Link (Symlink) Following in TP-Link Archer C9(US)_V1_180125 firmware allows an unauthenticated actor, with physical access…
- CVE-2020-57981 PoCinSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower…
- CVE-2020-58031 PoCRelative Path Traversal in Marvell QConvergeConsole GUI 5.5.0.74 allows a remote, authenticated attacker to delete arbitrary files on disk…
- CVE-2020-58091 PoCA stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into…
- CVE-2020-58101 PoCA stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a…
- CVE-2020-58113 PoCsAn authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in…
- CVE-2020-58251 PoCSymantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to…
- CVE-2020-58371 PoCSymantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replaced by symbolic…
- CVE-2020-58391 PoCSymantec Endpoint Detection And Response, prior to 4.4, may be susceptible to an information disclosure issue, which is a type of…
- CVE-2020-58422 PoCsCodoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI. The payload is,…
- CVE-2020-58444 PoCsindex.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious…
- CVE-2020-58474 PoCsKEVUnraid through 6.8.0 allows Remote Code Execution.
- CVE-2020-58493 PoCsKEVUnraid 6.8.0 allows authentication bypass.
- CVE-2020-590260 PoCsKEVIn BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User…
- CVE-2020-59031 PoCIn BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vulnerability exists…