|
209731
|
7.8 |
HIGH
Local
|
redox-os
|
redox
|
redox-os v0.1.0 was discovered to contain a use-after-free bug via the gethostbyaddr() function at /src/header/netdb/mod.rs.
|
CWE-416
Use After Free
|
CVE-2020-22429
|
2024-11-21 14:13 |
2023-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209732
|
6.1 |
MEDIUM
Network
|
boxbilling
|
boxbilling
|
Cross Site Scripting (XSS) vulnerability in BoxBilling 4.19, 4.19.1, 4.20, and 4.21 allows remote attackers to run arbitrary code via the message field on the submit new ticket form.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23647
|
2024-11-21 14:13 |
2023-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209733
|
6.1 |
MEDIUM
Network
|
zblogcn
|
zblogphp
|
Cross Site Scripting vulnerability found in ZblogCN ZblogPHP v.1.0 allows a local attacker to execute arbitrary code via a crafted payload in title parameter of the module management model.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23327
|
2024-11-21 14:13 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209734
|
7.5 |
HIGH
Network
|
jsish
|
jsish
|
An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the StringReplaceCmd function in the src/jsiChar.c file.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-23260
|
2024-11-21 14:13 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209735
|
7.5 |
HIGH
Network
|
jsish
|
jsish
|
An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the Jsi_Strlen function in the src/jsiChar.c file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-23259
|
2024-11-21 14:13 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209736
|
7.5 |
HIGH
Network
|
jsish
|
jsish
|
An issue found in Jsish v.3.0.11 allows a remote attacker to cause a denial of service via the Jsi_ValueIsNumber function in ./src/jsiValue.c file.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-23258
|
2024-11-21 14:13 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209737
|
7.5 |
HIGH
Network
|
espruino
|
espruino
|
Buffer Overflow vulnerability found in Espruino 2v05.41 allows an attacker to cause a denial of service via the function jsvGarbageCollectMarkUsed in file src/jsvar.c.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-23257
|
2024-11-21 14:13 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209738
|
6.1 |
MEDIUM
Network
|
easycorp
|
zentao
|
Cross Site Scripting vulnerability found in Zentao allows a remote attacker to execute arbitrary code via the lang parameter
|
CWE-79
Cross-site Scripting
|
CVE-2020-22533
|
2024-11-21 14:13 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209739
|
9.8 |
CRITICAL
Network
|
phpmyadmin
|
phpmyadmin
|
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.
|
CWE-89
SQL Injection
|
CVE-2020-22452
|
2024-11-21 14:13 |
2023-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209740
|
6.1 |
MEDIUM
Network
|
hfish_project
|
hfish
|
An issue was discovered in HFish 0.5.1. When a payload is inserted where the name is entered, XSS code is triggered when the administrator views the information.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22327
|
2024-11-21 14:13 |
2023-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|