|
209941
|
8.8 |
HIGH
Network
|
evertz
|
3080ipx_firmware 7801fc_firmware 7890ixg_firmware
|
EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upload, allowing an authenticated attacker to upload a webshell or overwrite any c…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-22159
|
2024-11-21 14:13 |
2023-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209942
|
8.8 |
HIGH
Network
|
verydows
|
verydows
|
Cross Site Request Forgery (CSRF) vulnerability found in Verytops Verydows all versions that allows an attacker to execute arbitrary code via a crafted script.
|
CWE-352
Origin Validation Error
|
CVE-2020-23363
|
2024-11-21 14:13 |
2023-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209943
|
9.8 |
CRITICAL
Network
|
ruckuswireless
|
r310_firmware r500_firmware r600_firmware t300_firmware t301n_firmware t301s_firmware scg200_firmware sz-100_firmware sz-300_firmware vsz_firmware zonedirector_1100_firm…
|
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before …
|
NVD-CWE-noinfo
|
CVE-2020-22654
|
2024-11-21 14:13 |
2023-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209944
|
6.5 |
MEDIUM
Network
|
optilinknetwork
|
op-xt71000n_firmware
|
A vulnerability in the "/admin/wlmultipleap.asp" of optilink OP-XT71000N version: V2.2 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to create …
|
CWE-352
Origin Validation Error
|
CVE-2020-23582
|
2024-11-21 14:13 |
2022-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209945
|
9.8 |
CRITICAL
Network
|
mkcms_project
|
mkcms
|
MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.
|
CWE-89
SQL Injection
|
CVE-2020-22820
|
2024-11-21 14:13 |
2022-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209946
|
- |
|
-
|
-
|
Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive information via crafted payload to Category name component.
|
-
|
CVE-2020-22540
|
2024-11-21 14:13 |
2024-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209947
|
- |
|
-
|
-
|
An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploading a crafted file.
|
-
|
CVE-2020-22539
|
2024-11-21 14:13 |
2024-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209948
|
9.8 |
CRITICAL
Network
|
mybb
|
mybb
|
Installer RCE on settings file write in MyBB before 1.8.22.
|
NVD-CWE-noinfo
|
CVE-2020-22612
|
2024-11-21 14:13 |
2023-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209949
|
5.5 |
MEDIUM
Local
|
tukaani
|
xz
|
An issue discovered in XZ 5.2.5 allows attackers to cause a denial of service via decompression of a crafted file. NOTE: the vendor disputes the claims of "endless output" and "denial of service" bec…
|
NVD-CWE-noinfo
|
CVE-2020-22916
|
2024-11-21 14:13 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209950
|
6.5 |
MEDIUM
Network
|
libraw
|
libraw
|
Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-22628
|
2024-11-21 14:13 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|