|
209731
|
3.3 |
LOW
Local
|
foxitsoftware
|
foxit_studio_photo
|
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in t…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-17420
|
2024-11-21 14:08 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209732
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_studio_photo
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-17419
|
2024-11-21 14:08 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209733
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_studio_photo
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-17418
|
2024-11-21 14:08 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209734
|
7.8 |
HIGH
Local
|
flowpaper
|
pdf2json
|
Buffer overflow in pdf2json 0.69 allows local users to execute arbitrary code by converting a crafted PDF file.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-18750
|
2024-11-21 14:08 |
2021-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209735
|
6.1 |
MEDIUM
Network
|
typora
|
typora
|
An issue was discovered in Typora 0.9.67. There is an XSS vulnerability that causes Remote Code Execution.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18737
|
2024-11-21 14:08 |
2021-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209736
|
9.8 |
CRITICAL
Network
|
zzzcms
|
zzzphp
|
SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php.
|
CWE-89
SQL Injection
|
CVE-2020-18717
|
2024-11-21 14:08 |
2021-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209737
|
9.8 |
CRITICAL
Network
|
rockoa
|
rockoa
|
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAction.php.
|
CWE-89
SQL Injection
|
CVE-2020-18716
|
2024-11-21 14:08 |
2021-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209738
|
9.8 |
CRITICAL
Network
|
rockoa
|
rockoa
|
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordModel.php's getdata function.
|
CWE-89
SQL Injection
|
CVE-2020-18714
|
2024-11-21 14:08 |
2021-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209739
|
9.8 |
CRITICAL
Network
|
rockoa
|
rockoa
|
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in customerAction.php
|
CWE-89
SQL Injection
|
CVE-2020-18713
|
2024-11-21 14:08 |
2021-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209740
|
5.4 |
MEDIUM
Network
|
altn
|
mdaemon_webmail
|
Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18724
|
2024-11-21 14:08 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|