|
208951
|
5.5 |
MEDIUM
Local
|
huawei
|
jackman-al00d_firmware
|
There is a resource management error vulnerability in Jackman-AL00D versions 8.2.0.185(C00R2P1). Local attackers construct malicious application files, causing system applications to run abnormally.
|
NVD-CWE-noinfo
|
CVE-2020-1848
|
2024-11-21 14:11 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208952
|
5.4 |
MEDIUM
Network
|
zzcms
|
zzcms
|
There is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via user/login.php
|
CWE-79
Cross-site Scripting
|
CVE-2020-20285
|
2024-11-21 14:11 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208953
|
9.8 |
CRITICAL
Network
|
troglobit
|
uftpd
|
There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server versions 2.7 to 2.10 due to improper implementation of a chroot jail in common.c's…
|
CWE-22
Path Traversal
|
CVE-2020-20277
|
2024-11-21 14:11 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208954
|
9.8 |
CRITICAL
Network
|
troglobit
|
uftpd
|
An unauthenticated stack-based buffer overflow vulnerability in common.c's handle_PORT in uftpd FTP server versions 2.10 and earlier can be abused to cause a crash and could potentially lead to remot…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-20276
|
2024-11-21 14:11 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208955
|
6.1 |
MEDIUM
Network
|
flexmonster
|
pivot_table_\&_charts
|
Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table & Charts 2.7.17.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20142
|
2024-11-21 14:11 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208956
|
6.1 |
MEDIUM
Network
|
flexmonster
|
pivot_table_\&_charts
|
Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20141
|
2024-11-21 14:11 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208957
|
6.1 |
MEDIUM
Network
|
flexmonster
|
pivot_table_\&_charts
|
Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20140
|
2024-11-21 14:11 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208958
|
6.1 |
MEDIUM
Network
|
flexmonster
|
pivot_table_\&_charts
|
Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20139
|
2024-11-21 14:11 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208959
|
6.1 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
Cross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20138
|
2024-11-21 14:11 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208960
|
9.8 |
CRITICAL
Network
|
newpk_project
|
newpk
|
SQL Injection vulnerability in NewPK 1.1 via the title parameter to admin\newpost.php.
|
CWE-89
SQL Injection
|
CVE-2020-20189
|
2024-11-21 14:11 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|