|
197821
|
5.4 |
MEDIUM
Network
|
baby_care_system_project
|
baby_care_system
|
Baby Care System 1.0 is affected by a cross-site scripting (XSS) vulnerability in the Edit Page tab through the Post title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35752
|
2024-11-21 14:28 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197822
|
7.2 |
HIGH
Network
|
zenphoto
|
zenphoto
|
Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the uploader plugin, check the elFinder box, and then drag a…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-36079
|
2024-11-21 14:28 |
2021-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197823
|
6.1 |
MEDIUM
Network
|
getgist
|
chatbox
|
Chatbox is affected by cross-site scripting (XSS). An attacker has to upload any XSS payload with SVG, XML file in Chatbox. There is no restriction on file upload in Chatbox which leads to stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35852
|
2024-11-21 14:28 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197824
|
6.5 |
MEDIUM
Network
|
digium
|
asterisk
|
A buffer overflow in res_pjsip_diversion.c in Sangoma Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1 allows remote attacker to crash Asterisk by deliberately misusing SIP 181 responses.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-35776
|
2024-11-21 14:28 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197825
|
7.5 |
HIGH
Network
|
online_book_store_project
|
online_book_store
|
The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads to the ability to retrieve all databases.
|
CWE-89
SQL Injection
|
CVE-2020-36003
|
2024-11-21 14:28 |
2021-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197826
|
7.5 |
HIGH
Network
|
seat-reservation-system_project
|
seat-reservation-system
|
Seat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id parameter where attackers can obtain sensitive database information.
|
CWE-89
SQL Injection
|
CVE-2020-36002
|
2024-11-21 14:28 |
2021-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197827
|
9.8 |
CRITICAL
Network
|
citsmart
|
citsmart
|
CITSmart before 9.1.2.23 allows LDAP Injection.
|
CWE-74
Injection
|
CVE-2020-35775
|
2024-11-21 14:28 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197828
|
6.5 |
MEDIUM
Network
|
imagely
|
nextgen_gallery
|
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parame…
|
CWE-352
Origin Validation Error
|
CVE-2020-35943
|
2024-11-21 14:28 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197829
|
8.8 |
HIGH
Network
|
imagely
|
nextgen_gallery
|
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execut…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2020-35942
|
2024-11-21 14:28 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197830
|
8.8 |
HIGH
Network
|
symonics fedoraproject
|
libmysofa fedora
|
Buffer overflow in readDataVar in hdf/dataobject.c in Symonics libmysofa 0.5 - 1.1 allows attackers to execute arbitrary code via a crafted SOFA.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-36152
|
2024-11-21 14:28 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|