|
200541
|
7.8 |
HIGH
Local
|
aplixio
|
pdf_shapingup
|
Aplioxio PDF ShapingUp 5.0.0.139 contains a buffer overflow which allows attackers to cause a denial of service (DoS) via a crafted PDF file.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-28969
|
2024-11-21 14:23 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200542
|
5.4 |
MEDIUM
Network
|
draytek
|
vigorap_1000c_firmware vigorap_700_firmware vigorap_710_firmware vigorap_800_firmware vigorap_802_firmware vigorap_810_firmware vigorap_900_firmware vigorap_902_firmware vigor…
|
Draytek VigorAP 1000C contains a stored cross-site scripting (XSS) vulnerability in the RADIUS Setting - RADIUS Server Configuration module. This vulnerability allows attackers to execute arbitrary w…
|
CWE-79
Cross-site Scripting
|
CVE-2020-28968
|
2024-11-21 14:23 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200543
|
8.8 |
HIGH
Network
|
flashget
|
flashget
|
FlashGet v1.9.6 was discovered to contain a buffer overflow in the 'current path directory' function. This vulnerability allows attackers to elevate local process privileges via overwriting the regis…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-28967
|
2024-11-21 14:23 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200544
|
6.7 |
MEDIUM
Local
|
tonec
|
internet_download_manager
|
Internet Download Manager 6.37.11.1 was discovered to contain a stack buffer overflow in the Search function. This vulnerability allows attackers to escalate local process privileges via unspecified …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-28964
|
2024-11-21 14:23 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200545
|
7.8 |
HIGH
Local
|
krylack
|
zip_password_recovery
|
Passcovery Co. Ltd ZIP Password Recovery v3.70.69.0 was discovered to contain a buffer overflow via the decompress function.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-28963
|
2024-11-21 14:23 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200546
|
5.4 |
MEDIUM
Network
|
perfexcrm
|
perfex_crm
|
Perfex CRM v2.4.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component ./clients/client via the company name parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28961
|
2024-11-21 14:23 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200547
|
9.8 |
CRITICAL
Network
|
cct95
|
chichen_tech_cms
|
Chichen Tech CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the file product_list.php via the id and cid parameters.
|
CWE-89
SQL Injection
|
CVE-2020-28960
|
2024-11-21 14:23 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200548
|
5.4 |
MEDIUM
Network
|
froxlor
|
froxlor
|
Multiple cross-site scripting (XSS) vulnerabilities in the Customer Add module of Foxlor v0.10.16 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the name…
|
CWE-79
Cross-site Scripting
|
CVE-2020-28957
|
2024-11-21 14:23 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200549
|
5.4 |
MEDIUM
Network
|
sugarcrm
|
sugarcrm
|
Multiple cross-site scripting (XSS) vulnerabilities in the Sales module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML via crafted payloads entered into the primary add…
|
CWE-79
Cross-site Scripting
|
CVE-2020-28956
|
2024-11-21 14:23 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200550
|
5.4 |
MEDIUM
Network
|
sugarcrm
|
sugarcrm
|
SugarCRM v6.5.18 was discovered to contain a cross-site scripting (XSS) vulnerability in the Create Employee module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a…
|
CWE-79
Cross-site Scripting
|
CVE-2020-28955
|
2024-11-21 14:23 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|