CVE-2020-7000 to CVE-2020-7999
216 CVEs with public proof-of-concept exploits.
- CVE-2020-70122 PoCsKibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker…
- CVE-2020-70301 PoCIPO Information Disclosure
- CVE-2020-70323 PoCsAvaya WebLM Improper Restriction of XML External Entity Reference
- CVE-2020-70482 PoCsThe WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the…
- CVE-2020-70521 PoCCODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of…
- CVE-2020-70541 PoCMmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c in libIEC61850 through 1.4.0 has a heap-based buffer overflow when…
- CVE-2020-70601 PoCglobal buffer-overflow in mbfl_filt_conv_big5_wchar
- CVE-2020-70621 PoCNull Pointer Dereference in PHP Session Upload Progress
- CVE-2020-70671 PoCOOB Read in urldecode()
- CVE-2020-70681 PoCUse of freed hash key in the phar_parse_zipfile function
- CVE-2020-71041 PoCThe chained-quiz plugin 1.1.8.1 for WordPress has reflected XSS via the wp-admin/admin-ajax.php total_questions parameter.
- CVE-2020-71071 PoCThe Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.
- CVE-2020-71084 PoCsThe LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.
- CVE-2020-71153 PoCsThe ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an…
- CVE-2020-71361 PoCA security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard…
- CVE-2020-72003 PoCsA potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerability could be…
- CVE-2020-72095 PoCsLinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
- CVE-2020-72104 PoCsUmbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.
- CVE-2020-72221 PoCAn issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with JavaScript when…
- CVE-2020-72271 PoCWestermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to…
- CVE-2020-72311 PoCEvoko Home 1.31 devices provide different error messages for failed login requests depending on whether the username is valid.
- CVE-2020-72321 PoCEvoko Home devices 1.31 through 1.37 allow remote attackers to obtain sensitive information (such as usernames and password hashes) via a…
- CVE-2020-72331 PoCKMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Logon.swf file.
- CVE-2020-72341 PoCRuckus ZoneFlex R310 104.0.0.0.1347 devices allow Stored XSS via the SSID field on the Configuration > Radio 2.4G > Wireless X screen…
- CVE-2020-72401 PoCMeinberg Lantime M300 and M1000 devices allow attackers (with privileges to configure a device) to execute arbitrary OS commands by…
- CVE-2020-72411 PoCThe WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory…
- CVE-2020-72421 PoCComtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the…
- CVE-2020-724618 PoCsA remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the…
- CVE-2020-724724 PoCsKEVsmtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary…
- CVE-2020-72491 PoCSMC D3G0804W 3.5.2.5-LAT_GA devices allow XSS via the SSID field on the WiFi Network Configuration page (after a successful login to the…
- CVE-2020-72571 PoCPrivilege Escalation vulnerability through Symbolic links in ENS
- CVE-2020-73181 PoCePolicy Orchistrator (ePO) - Cross-Site Scripting vulnerability
- CVE-2020-73501 PoCMetasploit Framework Plugin Libnotify Command Injection
- CVE-2020-73512 PoCsFonality Trixbox CE Post-Authentication Command Injection
- CVE-2020-73524 PoCsGOG Galaxy GalaxyClientService Privilege Escalation
- CVE-2020-73541 PoCRapid7 Metasploit Pro Stored XSS in 'host' field
- CVE-2020-73551 PoCRapid7 Metasploit Pro Stored XSS in 'notes' field
- CVE-2020-73562 PoCsCayin xPost SQL Injection
- CVE-2020-73572 PoCsCayin CMS Command Injection
- CVE-2020-73611 PoCZenTao Pro Command Injection
- CVE-2020-73631 PoCUCWeb UC Browser Address Bar Spooofing
- CVE-2020-73641 PoCUCWeb UC Browser Address Bar Spooofing
- CVE-2020-73691 PoCYandex Browser Address Bar Spooofing
- CVE-2020-73701 PoCDanyil Vasilenko Bolt Browser Address Bar Spooofing
- CVE-2020-73711 PoCRaise IT Solutions RITS Browser Address Bar Spooofing
- CVE-2020-73732 PoCsvBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an…
- CVE-2020-73741 PoCDocumalis Free PDF Editor / Free PDF Scanner Stack Based Buffer Overflow
- CVE-2020-73771 PoCRapid7 Metasploit Framework Relative Path Traversal in telpho10_credential_dump module
- CVE-2020-73782 PoCsCRIXP OpenCRX Unverified Password Change
- CVE-2020-73848 PoCsClient-Side Command Injection in Rapid7 Metasploit
- CVE-2020-73872 PoCsSage X3 AdxAdmin Exposure of Sensitive Information to an Unauthorized Actor
- CVE-2020-73882 PoCsSage X3 AdxAdmin Unauthenticated Command Execution Bypass by Spoofing
- CVE-2020-74573 PoCsIn FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before…
- CVE-2020-74612 PoCsIn FreeBSD 12.1-STABLE before r365010, 11.4-STABLE before r365011, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before…
- CVE-2020-74701 PoCSonoff TH 10 and 16 devices with firmware 6.6.0.21 allows XSS via the Friendly Name 1 field (after a successful login with the Web Admin…
- CVE-2020-74716 PoCsDjango 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg…
- CVE-2020-74732 PoCsIn certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x…
- CVE-2020-75931 PoCA vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (V1.81.01 - V1.81.03), LOGO! 8 BM (incl. SIPLUS variants)…
- CVE-2020-75941 PoCMultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by…
- CVE-2020-75961 PoCCodecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.
- CVE-2020-75971 PoCcodecov-node npm module before 3.6.5 allows remote attackers to execute arbitrary commands.The value provided as part of the gcov-root…
- CVE-2020-75985 PoCsminimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
- CVE-2020-76011 PoCgulp-scss-lint through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands to the "exec" function…
- CVE-2020-76022 PoCsnode-prompt-here through 1.0.1 allows execution of arbitrary commands. The "runCommand()" is called by "getDevices()" function in file…
- CVE-2020-76031 PoCclosure-compiler-stream through 0.1.15 allows execution of arbitrary commands. The argument "options" of the exports function in…
- CVE-2020-76041 PoCpulverizr through 0.7.0 allows execution of arbitrary commands. Within "lib/job.js", the variable "filename" can be controlled by the…
- CVE-2020-76051 PoCgulp-tape through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of 'gulp-tape' options.
- CVE-2020-76061 PoCdocker-compose-remote-api through 0.1.4 allows execution of arbitrary commands. Within 'index.js' of the package, the function…
- CVE-2020-76071 PoCgulp-styledocco through 0.0.3 allows execution of arbitrary commands. The argument 'options' of the exports function in 'index.js' can be…
- CVE-2020-76081 PoCyargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.
- CVE-2020-76091 PoCnode-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fromJSON()" can be…
- CVE-2020-76111 PoCAll versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request…
- CVE-2020-76131 PoCclamscan through 1.2.0 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the `_is_clamav_binary`…
- CVE-2020-76141 PoCnpm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated together without…
- CVE-2020-76151 PoCfsa through 0.5.1 is vulnerable to Command Injection. The first argument of 'execGitCommand()', located within 'lib/rep.js#63' can be…
- CVE-2020-76161 PoCexpress-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding…
- CVE-2020-76181 PoCsds through 3.2.0 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of the…
- CVE-2020-76241 PoCeffect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument.
- CVE-2020-76251 PoCop-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function.
- CVE-2020-76261 PoCkarma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.
- CVE-2020-76271 PoCnode-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument…
- CVE-2020-76291 PoCinstall-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.
- CVE-2020-76301 PoCgit-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument.
- CVE-2020-76321 PoCnode-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.
- CVE-2020-76331 PoCapiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri…
- CVE-2020-76341 PoCheroku-addonpool through 0.1.15 is vulnerable to Command Injection.
- CVE-2020-76351 PoCcompass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument.
- CVE-2020-76361 PoCadb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command function.
- CVE-2020-76371 PoCclass-transformer before 0.3.1 allow attackers to perform Prototype Pollution. The classToPlainFromExist function could be tricked into…
- CVE-2020-76382 PoCsconfinit through 0.3.0 is vulnerable to Prototype Pollution.The 'setDeepProperty' function could be tricked into adding or modifying…
- CVE-2020-76391 PoCeivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying…
- CVE-2020-76411 PoCPrototype Pollution
- CVE-2020-76421 PoClazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the video-embed plugin:…
- CVE-2020-76431 PoCpaypal-adaptive through 0.4.2 manipulation of JavaScript objects resulting in Prototype Pollution. The PayPal function could be tricked…
- CVE-2020-76441 PoCfun-map through 3.3.1 is vulnerable to Prototype Pollution. The function assocInM could be tricked into adding or modifying properties of…
- CVE-2020-76451 PoCAll versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in Linux operating…
- CVE-2020-76461 PoCcurlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
- CVE-2020-76491 PoCDirectory Traversal
- CVE-2020-76563 PoCsjquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>"…
- CVE-2020-76602 PoCsserialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js".
- CVE-2020-76611 PoCall versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long string in String.test…
- CVE-2020-76622 PoCswebsocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take…
- CVE-2020-76631 PoCwebsocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take…
- CVE-2020-76641 PoCArbitrary File Write via Archive Extraction (Zip Slip)
- CVE-2020-76651 PoCArbitrary File Write via Archive Extraction (Zip Slip)
- CVE-2020-76661 PoCArbitrary File Write via Archive Extraction (Zip Slip)
- CVE-2020-76671 PoCArbitrary File Write via Archive Extraction (Zip Slip)
- CVE-2020-76681 PoCArbitrary File Write via Archive Extraction (Zip Slip)
- CVE-2020-76691 PoCArbitrary File Write via Archive Extraction (Zip Slip)
- CVE-2020-76721 PoCmosc through 1.0.0 is vulnerable to Arbitrary Code Execution. User input provided to `properties` argument is executed by the `eval`…
- CVE-2020-76731 PoCnode-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. User input provided to the argument `A` of `extend`…
- CVE-2020-76741 PoCaccess-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the `template` function is executed by the…
- CVE-2020-76751 PoCcd-messenger through 2.7.26 is vulnerable to Arbitrary Code Execution. User input provided to the `color` argument executed by the `eval`…
- CVE-2020-76761 PoCangular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized…
- CVE-2020-76772 PoCsArbitrary Code Execution
- CVE-2020-76781 PoCArbitrary Code Execution
- CVE-2020-76792 PoCsPrototype Pollution
- CVE-2020-76803 PoCsdocsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters after # sign) to…
- CVE-2020-76811 PoCDirectory Traversal
- CVE-2020-76821 PoCDirectory Traversal
- CVE-2020-76831 PoCDirectory Traversal
- CVE-2020-76861 PoCDirectory Traversal
- CVE-2020-76871 PoCDirectory Traversal
- CVE-2020-76882 PoCsCommand Injection
- CVE-2020-76901 PoCAll affected versions <2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS). It is possible to inject JavaScript code via…
- CVE-2020-76915 PoCsCross-site Scripting (XSS)
- CVE-2020-76934 PoCsDenial of Service (DoS)
- CVE-2020-76941 PoCLog Injection
- CVE-2020-76951 PoCHTTP Response Splitting
- CVE-2020-76971 PoCCommand Injection
- CVE-2020-76996 PoCsPrototype Pollution
- CVE-2020-77001 PoCPrototype Pollution
- CVE-2020-77011 PoCPrototype Pollution
- CVE-2020-77021 PoCPrototype Pollution
- CVE-2020-77031 PoCPrototype Pollution
- CVE-2020-77041 PoCPrototype Pollution
- CVE-2020-77061 PoCPrototype Pollution
- CVE-2020-77072 PoCsPrototype Pollution
- CVE-2020-77082 PoCsPrototype Pollution
- CVE-2020-77092 PoCsPrototype Pollution
- CVE-2020-77101 PoCSandbox Escape
- CVE-2020-77123 PoCsCommand Injection
- CVE-2020-77131 PoCPrototype Pollution
- CVE-2020-77141 PoCPrototype Pollution
- CVE-2020-77151 PoCPrototype Pollution
- CVE-2020-77161 PoCPrototype Pollution
- CVE-2020-77171 PoCPrototype Pollution
- CVE-2020-77181 PoCPrototype Pollution
- CVE-2020-77192 PoCsPrototype Pollution
- CVE-2020-77203 PoCsPrototype Pollution
- CVE-2020-77211 PoCPrototype Pollution
- CVE-2020-77221 PoCPrototype Pollution
- CVE-2020-77231 PoCPrototype Pollution
- CVE-2020-77241 PoCPrototype Pollution
- CVE-2020-77251 PoCPrototype Pollution
- CVE-2020-77261 PoCPrototype Pollution
- CVE-2020-77271 PoCPrototype Pollution
- CVE-2020-77333 PoCsRegular Expression Denial of Service (ReDoS)
- CVE-2020-77342 PoCsCross-site Scripting (XSS)
- CVE-2020-77361 PoCPrototype Pollution
- CVE-2020-77371 PoCPrototype Pollution
- CVE-2020-77391 PoCServer-side Request Forgery (SSRF)
- CVE-2020-77451 PoCMalicious Package
- CVE-2020-77464 PoCsPrototype Pollution
- CVE-2020-77471 PoCCross-site Scripting (XSS)
- CVE-2020-77481 PoCPrototype Pollution
- CVE-2020-77491 PoCServer-side Request Forgery (SSRF)
- CVE-2020-77502 PoCsCross-site Scripting (XSS)
- CVE-2020-77511 PoCPrototype Pollution
- CVE-2020-77522 PoCsCommand Injection
- CVE-2020-77532 PoCsRegular Expression Denial of Service (ReDoS)
- CVE-2020-77571 PoCPath Traversal
- CVE-2020-77581 PoCPath Traversal
- CVE-2020-77607 PoCsRegular Expression Denial of Service (ReDoS)
- CVE-2020-77621 PoCArbitrary File Read
- CVE-2020-77632 PoCsArbitrary File Read
- CVE-2020-77651 PoCPrototype Pollution
- CVE-2020-77662 PoCsPrototype Pollution
- CVE-2020-77671 PoCRegular Expression Denial of Service (ReDoS)
- CVE-2020-77692 PoCsCommand Injection
- CVE-2020-77711 PoCPrototype Pollution
- CVE-2020-77721 PoCPrototype Pollution
- CVE-2020-77743 PoCsPrototype Pollution
- CVE-2020-77761 PoCCross-site Scripting (XSS)
- CVE-2020-77771 PoCArbitrary Code Execution
- CVE-2020-77811 PoCCommand Injection
- CVE-2020-77821 PoCCommand Injection
- CVE-2020-77841 PoCcommand_injection
- CVE-2020-77851 PoCCommand Injection
- CVE-2020-77861 PoCCommand Injection
- CVE-2020-77871 PoCImproper Authentication
- CVE-2020-77882 PoCsPrototype Pollution
- CVE-2020-77933 PoCsRegular Expression Denial of Service (ReDoS)
- CVE-2020-77951 PoCCommand Injection
- CVE-2020-77961 PoCKEVZimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.
- CVE-2020-77992 PoCsAn issue was discovered in FusionAuth before 1.11.0. An authenticated user, allowed to edit e-mail templates (Home -> Settings -> Email…
- CVE-2020-78421 PoCD'live AP command injection vulnerability
- CVE-2020-79151 PoCAn issue was discovered on Eaton 5P 850 devices. The Ubicacion SAI field allows XSS attacks by an administrator.
- CVE-2020-79211 PoCAdministrative action may disable enforcement of per-user IP whitelisting
- CVE-2020-79311 PoCIn JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modifying a…
- CVE-2020-79342 PoCsIn LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are…
- CVE-2020-79431 PoCPuppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may…
- CVE-2020-79491 PoCschemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming…
- CVE-2020-79592 PoCsLabVantage LIMS 8.3 does not properly maintain the confidentiality of database names. For example, the web application exposes the…
- CVE-2020-796116 PoCsKEVDeserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web…
- CVE-2020-79807 PoCsIntellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the…
- CVE-2020-79821 PoCAn issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the opkg package…
- CVE-2020-79842 PoCsSolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials…
- CVE-2020-79881 PoCAn issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to…
- CVE-2020-79891 PoCAdive Framework 2.0.8 has admin/user/add userUsername XSS.
- CVE-2020-79901 PoCAdive Framework 2.0.8 has admin/user/add userName XSS.
- CVE-2020-79913 PoCsAdive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
- CVE-2020-79952 PoCsThe htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.
- CVE-2020-79961 PoChtdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows XSS via the Referer HTTP header.
- CVE-2020-79971 PoCASUS WRT-AC66U 3 RT 3.0.0.4.372_67 devices allow XSS via the Client Name field to the Parental Control feature.
- CVE-2020-79991 PoCThe Intellian Aptus application 1.0.2 for Android has hardcoded values for DOWNLOAD_API_KEY and FILE_DOWNLOAD_API_KEY.