|
197621
|
5.4 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add Shortcut" pa…
|
CWE-79
Cross-site Scripting
|
CVE-2020-36408
|
2024-11-21 14:29 |
2021-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197622
|
5.4 |
MEDIUM
Network
|
phplist
|
phplist
|
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "rule1" parameter under the "Bounce…
|
CWE-79
Cross-site Scripting
|
CVE-2020-36399
|
2024-11-21 14:29 |
2021-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197623
|
5.4 |
MEDIUM
Network
|
phplist
|
phplist
|
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "Campaign" field under the "Send a …
|
CWE-79
Cross-site Scripting
|
CVE-2020-36398
|
2024-11-21 14:29 |
2021-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197624
|
5.4 |
MEDIUM
Network
|
lavalite
|
lavalite
|
A stored cross site scripting (XSS) vulnerability in the /admin/contact/contact component of LavaLite 5.8.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted paylo…
|
CWE-79
Cross-site Scripting
|
CVE-2020-36397
|
2024-11-21 14:29 |
2021-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197625
|
5.4 |
MEDIUM
Network
|
lavalite
|
lavalite
|
A stored cross site scripting (XSS) vulnerability in the /admin/roles/role component of LavaLite 5.8.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload en…
|
CWE-79
Cross-site Scripting
|
CVE-2020-36396
|
2024-11-21 14:29 |
2021-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197626
|
5.4 |
MEDIUM
Network
|
lavalite
|
lavalite
|
A stored cross site scripting (XSS) vulnerability in the /admin/user/team component of LavaLite 5.8.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload ent…
|
CWE-79
Cross-site Scripting
|
CVE-2020-36395
|
2024-11-21 14:29 |
2021-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197627
|
8.8 |
HIGH
Network
|
aomedia
|
libavif
|
libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-36407
|
2024-11-21 14:29 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197628
|
8.8 |
HIGH
Network
|
uwebsockets_project
|
uwebsockets
|
uWebSockets 18.11.0 and 18.12.0 has a stack-based buffer overflow in uWS::TopicTree::trimTree (called from uWS::TopicTree::unsubscribeAll). NOTE: the vendor's position is that this is "a minor issue …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-36406
|
2024-11-21 14:29 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197629
|
7.8 |
HIGH
Local
|
keystone-engine
|
keystone_engine
|
Keystone Engine 0.9.2 has a use-after-free in llvm_ks::X86Operand::getToken.
|
CWE-416
Use After Free
|
CVE-2020-36405
|
2024-11-21 14:29 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197630
|
7.8 |
HIGH
Local
|
keystone-engine
|
keystone
|
Keystone Engine 0.9.2 has an invalid free in llvm_ks::SmallVectorImpl<llvm_ks::MCFixup>::~SmallVectorImpl.
|
CWE-763
Release of Invalid Pointer or Reference
|
CVE-2020-36404
|
2024-11-21 14:29 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|