|
199761
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_applications_manager
|
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
|
CWE-89
SQL Injection
|
CVE-2020-28679
|
2024-11-21 14:23 |
2022-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199762
|
7.5 |
HIGH
Network
|
sphinxsearch debian
|
sphinx debian_linux
|
SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operation…
|
CWE-22
Path Traversal
|
CVE-2020-29050
|
2024-11-21 14:23 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199763
|
6.5 |
MEDIUM
Network
|
iball
|
wrd12en_firmware
|
iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or modifying the range for IP addresses.
|
CWE-352
Origin Validation Error
|
CVE-2020-29292
|
2024-11-21 14:23 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199764
|
9.1 |
CRITICAL
Network
|
zblogcn
|
z-blogphp
|
Z-BlogPHP v1.6.1.2100 was discovered to contain an arbitrary file deletion vulnerability via \app_del.php.
|
NVD-CWE-Other
|
CVE-2020-29177
|
2024-11-21 14:23 |
2021-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199765
|
7.8 |
HIGH
Local
|
zblogcn
|
z-blogphp
|
An arbitrary file upload vulnerability in Z-BlogPHP v1.6.1.2100 allows attackers to execute arbitrary code via a crafted JPG file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-29176
|
2024-11-21 14:23 |
2021-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199766
|
7.5 |
HIGH
Network
|
pybbs_project
|
pybbs
|
A SQL injection vulnerability in TopicMapper.xml of PybbsCMS v5.2.1 allows attackers to access sensitive database information.
|
CWE-89
SQL Injection
|
CVE-2020-28702
|
2024-11-21 14:23 |
2021-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199767
|
7.8 |
HIGH
Local
|
aplixio
|
pdf_shapingup
|
Aplioxio PDF ShapingUp 5.0.0.139 contains a buffer overflow which allows attackers to cause a denial of service (DoS) via a crafted PDF file.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-28969
|
2024-11-21 14:23 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199768
|
5.4 |
MEDIUM
Network
|
draytek
|
vigorap_1000c_firmware vigorap_700_firmware vigorap_710_firmware vigorap_800_firmware vigorap_802_firmware vigorap_810_firmware vigorap_900_firmware vigorap_902_firmware vigor…
|
Draytek VigorAP 1000C contains a stored cross-site scripting (XSS) vulnerability in the RADIUS Setting - RADIUS Server Configuration module. This vulnerability allows attackers to execute arbitrary w…
|
CWE-79
Cross-site Scripting
|
CVE-2020-28968
|
2024-11-21 14:23 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199769
|
8.8 |
HIGH
Network
|
flashget
|
flashget
|
FlashGet v1.9.6 was discovered to contain a buffer overflow in the 'current path directory' function. This vulnerability allows attackers to elevate local process privileges via overwriting the regis…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-28967
|
2024-11-21 14:23 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199770
|
6.7 |
MEDIUM
Local
|
tonec
|
internet_download_manager
|
Internet Download Manager 6.37.11.1 was discovered to contain a stack buffer overflow in the Search function. This vulnerability allows attackers to escalate local process privileges via unspecified …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-28964
|
2024-11-21 14:23 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|