CVE-2020-6000 to CVE-2020-6999
167 CVEs with public proof-of-concept exploits.
- CVE-2020-60071 PoCPhilips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handling a long ZCL…
- CVE-2020-60091 PoCLearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.
- CVE-2020-60102 PoCsLearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
- CVE-2020-60191 PoCValve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function…
- CVE-2020-60581 PoCAn exploitable out-of-bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted…
- CVE-2020-60611 PoCAn exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted…
- CVE-2020-60621 PoCAn exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP…
- CVE-2020-60631 PoCAn exploitable out-of-bounds write vulnerability exists in the uncompress_scan_line function of the igcore19d.dll library of Accusoft…
- CVE-2020-60641 PoCAn exploitable out-of-bounds write vulnerability exists in the uncompress_scan_line function of the igcore19d.dll library of Accusoft…
- CVE-2020-60651 PoCAn exploitable out-of-bounds write vulnerability exists in the bmp_parsing function of the igcore19d.dll library of Accusoft ImageGear,…
- CVE-2020-60661 PoCAn exploitable out-of-bounds write vulnerability exists in the igcore19d.dll JPEG SOFx parser of the Accusoft ImageGear 19.5.0 library. A…
- CVE-2020-60671 PoCAn exploitable out-of-bounds write vulnerability exists in the igcore19d.dll TIFF tifread parser of the Accusoft ImageGear 19.5.0 library.…
- CVE-2020-60681 PoCAn exploitable out-of-bounds write vulnerability exists in the igcore19d.dll PNG pngread parser of the Accusoft ImageGear 19.5.0 library.…
- CVE-2020-60691 PoCAn exploitable out-of-bounds write vulnerability exists in the igcore19d.dll JPEG jpegread precision parser of the Accusoft ImageGear…
- CVE-2020-60701 PoCAn exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A specially crafted f2fs…
- CVE-2020-60711 PoCAn exploitable denial-of-service vulnerability exists in the resource record-parsing functionality of Videolabs libmicrodns 0.1.0. When…
- CVE-2020-60721 PoCAn exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing…
- CVE-2020-60731 PoCAn exploitable denial-of-service vulnerability exists in the TXT record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing…
- CVE-2020-60741 PoCAn exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a…
- CVE-2020-60751 PoCAn exploitable out-of-bounds write vulnerability exists in the store_data_buffer function of the igcore19d.dll library of Accusoft…
- CVE-2020-60761 PoCAn exploitable out-of-bounds write vulnerability exists in the igcore19d.dll ICO icoread parser of the Accusoft ImageGear 19.5.0 library.…
- CVE-2020-60771 PoCAn exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing…
- CVE-2020-60781 PoCAn exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing…
- CVE-2020-60791 PoCAn exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When…
- CVE-2020-60801 PoCAn exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When…
- CVE-2020-60811 PoCAn exploitable code execution vulnerability exists in the PLC_Task functionality of 3S-Smart Software Solutions GmbH CODESYS Runtime…
- CVE-2020-60821 PoCAn exploitable out-of-bounds write vulnerability exists in the ico_read function of the igcore19d.dll library of Accusoft ImageGear…
- CVE-2020-60831 PoCAn exploitable denial of service vulnerability exists in the ENIP Request Path Port Segment functionality of Allen-Bradley Flex IO…
- CVE-2020-60841 PoCAn exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO…
- CVE-2020-60851 PoCAn exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO…
- CVE-2020-60861 PoCAn exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO…
- CVE-2020-60871 PoCAn exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO…
- CVE-2020-60881 PoCAn exploitable denial of service vulnerability exists in the ENIP Request Path Network Segment functionality of Allen-Bradley Flex IO…
- CVE-2020-60891 PoCAn exploitable code execution vulnerability exists in the ANI file format parser of Leadtools 20. A specially crafted ANI file can cause a…
- CVE-2020-60921 PoCAn exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects. A specially crafted PDF file…
- CVE-2020-60931 PoCAn exploitable information disclosure vulnerability exists in the way Nitro Pro 13.9.1.155 does XML error handling. A specially crafted…
- CVE-2020-60941 PoCAn exploitable code execution vulnerability exists in the TIFF fillinraster function of the igcore19d.dll library of Accusoft ImageGear…
- CVE-2020-60961 PoCAn exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on…
- CVE-2020-60971 PoCAn exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially…
- CVE-2020-60981 PoCAn exploitable denial of service vulnerability exists in the freeDiameter functionality of freeDiameter 1.3.2. A specially crafted…
- CVE-2020-60991 PoCAn exploitable code execution vulnerability exists in the file format parsing functionality of Graphisoft BIMx Desktop Viewer 2019.2.2328.…
- CVE-2020-61001 PoCAn exploitable memory corruption vulnerability exists in AMD atidxx64.dll 26.20.15019.19000 graphics driver. A specially crafted pixel…
- CVE-2020-61011 PoCAn exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll…
- CVE-2020-61021 PoCAn exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll…
- CVE-2020-61031 PoCAn exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll…
- CVE-2020-61041 PoCAn exploitable information disclosure vulnerability exists in the get_dnode_of_data functionality of F2fs-Tools F2fs.Fsck 1.13. A…
- CVE-2020-61051 PoCAn exploitable code execution vulnerability exists in the multiple devices functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted…
- CVE-2020-61061 PoCAn exploitable information disclosure vulnerability exists in the init_node_manager functionality of F2fs-Tools F2fs.Fsck 1.12 and 1.13. A…
- CVE-2020-61071 PoCAn exploitable information disclosure vulnerability exists in the dev_read functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted…
- CVE-2020-61081 PoCAn exploitable code execution vulnerability exists in the fsck_chk_orphan_node functionality of F2fs-Tools F2fs.Fsck 1.13. A specially…
- CVE-2020-61091 PoCAn exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs. A…
- CVE-2020-61101 PoCAn exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code…
- CVE-2020-61121 PoCAn exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro…
- CVE-2020-61131 PoCAn exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when…
- CVE-2020-61141 PoCAn exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit…
- CVE-2020-61151 PoCAn exploitable vulnerability exists in the cross-reference table repairing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242.…
- CVE-2020-61161 PoCAn arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When…
- CVE-2020-61171 PoCSQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The bday parameter in the page…
- CVE-2020-61181 PoCSQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The bmonth parameter in the page…
- CVE-2020-61191 PoCSQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The byear parameter in the page…
- CVE-2020-61201 PoCSQL injection vulnerability exists in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The fn parameter in the page…
- CVE-2020-61211 PoCSQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The ln parameter in the page…
- CVE-2020-61221 PoCSQL injection vulnerability exists in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The mn parameter in the page…
- CVE-2020-61231 PoCAn exploitable sql injection vulnerability exists in the email parameter functionality of OS4Ed openSIS 7.3. The email parameter in the…
- CVE-2020-61241 PoCAn exploitable sql injection vulnerability exists in the email parameter functionality of OS4Ed openSIS 7.3. The email parameter in the…
- CVE-2020-61251 PoCAn exploitable SQL injection vulnerability exists in the GetSchool.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP…
- CVE-2020-61261 PoCSQL injection vulnerability exists in the CoursePeriodModal.php page of OS4Ed openSIS 7.3. The course_period_id parameter in the page…
- CVE-2020-61271 PoCSQL injection vulnerability exists in the CoursePeriodModal.php page of OS4Ed openSIS 7.3. The id parameter in the page…
- CVE-2020-61281 PoCSQL injection vulnerability exists in the CoursePeriodModal.php page of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to…
- CVE-2020-61291 PoCSQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages. The course_period_id parameter in…
- CVE-2020-61301 PoCSQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages. The course_period_id parameter in…
- CVE-2020-61311 PoCSQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages. The course_period_id parameter in…
- CVE-2020-61321 PoCSQL injection vulnerability exists in the ID parameters of OS4Ed openSIS 7.3 pages. The id parameter in the page ChooseCP.php is…
- CVE-2020-61331 PoCSQL injection vulnerabilities exist in the ID parameters of OS4Ed openSIS 7.3 pages. The id parameter in the page CourseMoreInfo.php is…
- CVE-2020-61341 PoCSQL injection vulnerabilities exist in the ID parameters of OS4Ed openSIS 7.3 pages. The id parameter in the page MassDropModal.php is…
- CVE-2020-61351 PoCAn exploitable SQL injection vulnerability exists in the Validator.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP…
- CVE-2020-61361 PoCAn exploitable SQL injection vulnerability exists in the DownloadWindow.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP…
- CVE-2020-61371 PoCSQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The password_stf_email parameter in the…
- CVE-2020-61381 PoCSQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The uname parameter in the password reset…
- CVE-2020-61391 PoCSQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The username_stf_email parameter in the…
- CVE-2020-61401 PoCSQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The password_stf_email parameter in the…
- CVE-2020-61411 PoCAn exploitable SQL injection vulnerability exists in the login functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can…
- CVE-2020-61421 PoCA remote code execution vulnerability exists in the Modules.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can…
- CVE-2020-61431 PoCA remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The password variable which is set at line…
- CVE-2020-61441 PoCA remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The username variable which is set at line…
- CVE-2020-61451 PoCAn SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request…
- CVE-2020-61461 PoCAn exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300. When drawing…
- CVE-2020-61471 PoCA heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. This…
- CVE-2020-61481 PoCA heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. An instance…
- CVE-2020-61491 PoCA heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. To trigger…
- CVE-2020-61501 PoCA heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software USDC file format SPECS section decompression heap overflow.
- CVE-2020-61521 PoCA code execution vulnerability exists in the DICOM parse_dicom_meta_info functionality of Accusoft ImageGear 19.7. A specially crafted…
- CVE-2020-61551 PoCA heap overflow vulnerability exists in the Pixar OpenUSD 20.05 while parsing compressed value rep arrays in binary USD files. A specially…
- CVE-2020-61561 PoCA heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. To trigger…
- CVE-2020-61661 PoCA flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to…
- CVE-2020-61671 PoCA flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode,…
- CVE-2020-61681 PoCA flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to…
- CVE-2020-61702 PoCsAn authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext…
- CVE-2020-61712 PoCsA cross-site scripting (XSS) vulnerability in the index page of the CLink Office 2.0 management console allows remote attackers to inject…
- CVE-2020-62076 PoCsKEVSAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication…
- CVE-2020-62863 PoCsThe insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard),…
- CVE-2020-62878 PoCsKEVSAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows…
- CVE-2020-63085 PoCsSAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject…
- CVE-2020-63182 PoCsA Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release…
- CVE-2020-63641 PoCSAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a…
- CVE-2020-63831 PoCType confusion in V8 in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2020-64189 PoCsKEVType confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2020-64682 PoCsType confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted…
- CVE-2020-65075 PoCsOut of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2020-65145 PoCsInappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to…
- CVE-2020-65161 PoCPolicy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2020-65193 PoCsPolicy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML…
- CVE-2020-65551 PoCOut of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obtain potentially sensitive information…
- CVE-2020-65771 PoCThe IT-Recht Kanzlei plugin in Zen Cart 1.5.6c (German edition) allows itrk-api.php rechtstext_language SQL Injection.
- CVE-2020-65781 PoCZen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_page.php or…
- CVE-2020-65791 PoCCross-site scripting (XSS) vulnerability in mailhive/cloudbeez/cloudloader.php and mailhive/cloudbeez/cloudloader_core.php in the MailBeez…
- CVE-2020-65811 PoCNagios NRPE 3.2.1 has Insufficient Filtering because, for example, nasty_metachars interprets \n as the character \ and the character n…
- CVE-2020-65821 PoCNagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive…
- CVE-2020-66091 PoCGNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.
- CVE-2020-66101 PoCGNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c.
- CVE-2020-66111 PoCGNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c.
- CVE-2020-66121 PoCGNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.
- CVE-2020-66131 PoCGNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.
- CVE-2020-66141 PoCGNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
- CVE-2020-66151 PoCGNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl).
- CVE-2020-66171 PoCstb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int.
- CVE-2020-66181 PoCstb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__find_table.
- CVE-2020-66191 PoCstb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek.
- CVE-2020-66201 PoCstb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_get8.
- CVE-2020-66211 PoCstb stb_truetype.h through 1.22 has a heap-based buffer over-read in ttUSHORT.
- CVE-2020-66221 PoCstb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_peek8.
- CVE-2020-66231 PoCstb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index.
- CVE-2020-66241 PoCjhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.
- CVE-2020-66251 PoCjhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c.
- CVE-2020-66272 PoCsThe web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via…
- CVE-2020-66281 PoCMing (aka libming) 0.4.8 has a heap-based buffer over-read in the function decompile_SWITCH() in decompile.c.
- CVE-2020-66291 PoCMing (aka libming) 0.4.8 has z NULL pointer dereference in the function decompileGETURL2() in decompile.c.
- CVE-2020-66301 PoCAn issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_isom_get_media_data_size() in…
- CVE-2020-66311 PoCAn issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_m2ts_stream_process_pmt() in…
- CVE-2020-66372 PoCsopenSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.
- CVE-2020-66501 PoCArbitrary code execution through “Update Manager” Class
- CVE-2020-67563 PoCslanguageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute…
- CVE-2020-67571 PoCcontentHostProperties.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows authenticated attackers to remotely execute…
- CVE-2020-67581 PoCA cross-site scripting (XSS) vulnerability in Option/optionsAll.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows…
- CVE-2020-68021 PoCIn Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted…
- CVE-2020-68161 PoCIn Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword…
- CVE-2020-68171 PoCbleach.clean behavior parsing style attributes could result in a regular expression denial of service (ReDoS). Calls to bleach.clean with…
- CVE-2020-68361 PoCgrammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package…
- CVE-2020-68381 PoCIn mruby 2.1.0, there is a use-after-free in hash_values_at in mrbgems/mruby-hash-ext/src/hash-ext.c.
- CVE-2020-68391 PoCIn mruby 2.1.0, there is a stack-based buffer overflow in mrb_str_len_to_dbl in string.c.
- CVE-2020-68401 PoCIn mruby 2.1.0, there is a use-after-free in hash_slice in mrbgems/mruby-hash-ext/src/hash-ext.c.
- CVE-2020-68433 PoCsZoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-83959.
- CVE-2020-68441 PoCIn TopManage OLK 2020, login CSRF can be chained with another vulnerability in order to takeover admin and user accounts.
- CVE-2020-68451 PoCAn issue was discovered in TopManage OLK 2020. As there is no ReadOnly on the Session cookie, the user and admin accounts can be taken…
- CVE-2020-68471 PoCOpenTrade through 0.2.0 has a DOM-based XSS vulnerability that is executed when an administrator attempts to delete a message that…
- CVE-2020-68491 PoCThe marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with resultant XSS.
- CVE-2020-68502 PoCsUtilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML XML Response to…
- CVE-2020-68511 PoCOpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of…
- CVE-2020-68577 PoCsCarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FTP server passwords…
- CVE-2020-68582 PoCsHotels Styx through 1.0.0.beta8 allows HTTP response splitting due to CRLF Injection. This is exploitable if untrusted user input can…
- CVE-2020-68601 PoClibmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header message attribute.
- CVE-2020-68612 PoCsA flawed protocol design in the Ledger Monero app before 1.5.1 for Ledger Nano and Ledger S devices allows a local attacker to extract the…
- CVE-2020-68622 PoCsV6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to…
- CVE-2020-69501 PoCDirectory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
- CVE-2020-69541 PoCAn issue was discovered on Cayin SMP-PRO4 devices. A user can discover a saved password by viewing the URL after a Connection String Test.…
- CVE-2020-69551 PoCAn issue was discovered on Cayin SMP-PRO4 devices. They allow image_preview.html?filename= reflected XSS.
- CVE-2020-69583 PoCsAn XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows…