|
210021
|
5.5 |
MEDIUM
Local
|
irfanview
|
irfanview
|
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000005722.
|
NVD-CWE-noinfo
|
CVE-2020-23561
|
2024-11-21 14:13 |
2022-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210022
|
8.1 |
HIGH
Network
|
microstrategy
|
microstrategy_web
|
A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-22983
|
2024-11-21 14:13 |
2022-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210023
|
6.1 |
MEDIUM
Network
|
microstrategy
|
microstrategy_web_sdk
|
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the fileToUpload parameter to the uploadFile…
|
CWE-79
Cross-site Scripting
|
CVE-2020-22987
|
2024-11-21 14:13 |
2022-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210024
|
6.1 |
MEDIUM
Network
|
microstrategy
|
microstrategy_web_sdk
|
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the searchString parameter to the wikiScrapp…
|
CWE-79
Cross-site Scripting
|
CVE-2020-22986
|
2024-11-21 14:13 |
2022-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210025
|
6.1 |
MEDIUM
Network
|
microstrategy
|
microstrategy_web_sdk
|
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig …
|
CWE-79
Cross-site Scripting
|
CVE-2020-22985
|
2024-11-21 14:13 |
2022-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210026
|
6.1 |
MEDIUM
Network
|
microstrategy
|
microstrategy_web_sdk
|
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via key parameter to the getGoogleExtraConfig ta…
|
CWE-79
Cross-site Scripting
|
CVE-2020-22984
|
2024-11-21 14:13 |
2022-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210027
|
9.8 |
CRITICAL
Network
|
squire-technologies
|
svi_ms_management_system
|
The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow at…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-23621
|
2024-11-21 14:13 |
2022-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210028
|
9.8 |
CRITICAL
Network
|
orlansoft
|
orlansoft_erp
|
The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-23620
|
2024-11-21 14:13 |
2022-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210029
|
6.1 |
MEDIUM
Network
|
xtendtech
|
voice_logger
|
A reflected cross site scripting (XSS) vulnerability in Xtend Voice Logger 1.0 allows attackers to execute arbitrary web scripts or HTML, via the path of the error page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23618
|
2024-11-21 14:13 |
2022-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210030
|
6.1 |
MEDIUM
Network
|
totolink
|
n200re_firmware n100re_firmware
|
A cross site scripting (XSS) vulnerability in the error page of Totolink N200RE and N100RE Routers 2.0 allows attackers to execute arbitrary web scripts or HTML via SCRIPT element.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23617
|
2024-11-21 14:13 |
2022-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|