|
198201
|
5.4 |
MEDIUM
Network
|
egavilanmedia
|
phpcrud
|
Stored Cross Site Scripting (XSS) vulnerability in EGavilan Media CRUD Operation with PHP, MySQL, Bootstrap, and Dompdf via First Name or Last Name parameter in the 'Add New Record Feature'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-36115
|
2024-11-21 14:28 |
2021-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198202
|
7.2 |
HIGH
Network
|
opensolution
|
quick.cms quick.cart
|
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab.
|
CWE-94
Code Injection
|
CVE-2020-35754
|
2024-11-21 14:28 |
2021-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198203
|
4.8 |
MEDIUM
Network
|
bdtask
|
multi-store
|
Stored XSS vulnerability in BDTASK Multi-Store Inventory Management System 1.0 allows a local admin to inject arbitrary code via the Customer Name Field.
|
CWE-79
Cross-site Scripting
|
CVE-2020-36012
|
2024-11-21 14:28 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198204
|
4.8 |
MEDIUM
Network
|
qdocs
|
smart_hospital
|
A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject arbitrary code via the Name, Guardian Name, Email, Address, Rem…
|
CWE-79
Cross-site Scripting
|
CVE-2020-36011
|
2024-11-21 14:28 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198205
|
4.8 |
MEDIUM
Network
|
textpattern
|
textpattern
|
Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35854
|
2024-11-21 14:28 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198206
|
4.8 |
MEDIUM
Network
|
4homepages
|
4images
|
4images Image Gallery Management System 1.7.11 is affected by cross-site scripting (XSS) in the Image URL. This vulnerability can result in an attacker to inject the XSS payload into the IMAGE URL. E…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35853
|
2024-11-21 14:28 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198207
|
7.8 |
HIGH
Local
|
faststone
|
image_viewer
|
FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0x96cf.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35845
|
2024-11-21 14:28 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198208
|
7.8 |
HIGH
Local
|
faststone
|
image_viewer
|
FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0xbe9c4.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35844
|
2024-11-21 14:28 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198209
|
5.5 |
MEDIUM
Local
|
faststone
|
image_viewer
|
FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0x956e.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35843
|
2024-11-21 14:28 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198210
|
6.1 |
MEDIUM
Network
|
persis
|
human_resource_management_portal
|
The job posting recommendation form in Persis Human Resource Management Portal (Versions 17.2.00 through 17.2.35 and 19.0.00 through 19.0.20), when the "Recommend job posting" function is enabled, al…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35753
|
2024-11-21 14:28 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|