|
209831
|
9.8 |
CRITICAL
Network
|
online_course_registration_project
|
online_course_registration
|
A File Upload vulnerability in SourceCodester Online Course Registration v1.0 allows remote attackers to achieve Remote Code Execution (RCE) on the hosting webserver by uploading a crafted PHP web-sh…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-23828
|
2024-11-21 14:14 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209832
|
9.1 |
CRITICAL
Network
|
trendmicro
|
serverprotect
|
A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrary code on an affected system. An attacker must first obtain admin/root privileg…
|
CWE-77
Command Injection
|
CVE-2020-24561
|
2024-11-21 14:14 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209833
|
7.6 |
HIGH
Physics
|
intel
|
core_i7-8665ue_firmware core_i7-8665u_firmware core_i7-8557u_firmware core_i7-8850h_firmware core_i7-8809g_firmware core_i7-8750h_firmware core_i7-8709g_firmware core_i7-8706g_fi…
|
Logic error in BIOS firmware for 8th, 9th and 10th Generation Intel(R) Core(TM) Processors may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or in…
|
NVD-CWE-noinfo
|
CVE-2020-24457
|
2024-11-21 14:14 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209834
|
8.8 |
HIGH
Network
|
argosoft
|
mail_server
|
ArGo Soft Mail Server 1.8.8.9 is affected by Cross Site Request Forgery (CSRF) for perform remote arbitrary code execution. The component is the Administration dashboard. When using admin/user creden…
|
CWE-352
Origin Validation Error
|
CVE-2020-23824
|
2024-11-21 14:14 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209835
|
7.8 |
HIGH
Local
|
taoensso
|
nippy
|
A deserialization flaw is present in Taoensso Nippy before 2.14.2. In some circumstances, it is possible for an attacker to create a malicious payload that, when deserialized, will allow arbitrary co…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-24164
|
2024-11-21 14:14 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209836
|
7.2 |
HIGH
Network
|
atoptechnology
|
se5901_firmware se5901b_firmware se5904d_firmware se5908_firmware se5908a_firmware se5916_firmware se5916a_firmware
|
Atop Technology industrial 3G/4G gateway contains Command Injection vulnerability. Due to insufficient input validation, the device's web management interface allows attackers to inject specific code…
|
CWE-78
OS Command
|
CVE-2020-24552
|
2024-11-21 14:14 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209837
|
9.8 |
CRITICAL
Network
|
yaws debian canonical
|
yaws debian_linux ubuntu_linux
|
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
|
CWE-611
XXE
|
CVE-2020-24379
|
2024-11-21 14:14 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209838
|
9.8 |
CRITICAL
Network
|
projectworlds
|
car_rental_project
|
Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-24199
|
2024-11-21 14:14 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209839
|
6.1 |
MEDIUM
Network
|
stock_management_system_project
|
stock_management_system
|
A persistent cross-site scripting vulnerability in Sourcecodester Stock Management System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'Brand Name.'
|
CWE-79
Cross-site Scripting
|
CVE-2020-24198
|
2024-11-21 14:14 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209840
|
9.1 |
CRITICAL
Network
|
online_bike_rental_project
|
online_bike_rental
|
An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated administrator to conduct remote code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-24195
|
2024-11-21 14:14 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|