|
210351
|
9.8 |
CRITICAL
Network
|
total-soft
|
responsive_poll
|
An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clone, or view a hidden poll. This is due to the usage…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-11673
|
2024-11-21 13:58 |
2020-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210352
|
7.5 |
HIGH
Network
|
davidlingren
|
media_library_assistant
|
The Media Library Assistant plugin before 2.82 for Wordpress suffers from a Local File Inclusion vulnerability in mla_gallery link=download.
|
NVD-CWE-noinfo
|
CVE-2020-11732
|
2024-11-21 13:58 |
2020-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210353
|
6.1 |
MEDIUM
Network
|
davidlingren
|
media_library_assistant
|
The Media Library Assistant plugin before 2.82 for Wordpress suffers from multiple XSS vulnerabilities in all Settings/Media Library Assistant tabs, which allow remote authenticated users to execute …
|
CWE-79
Cross-site Scripting
|
CVE-2020-11731
|
2024-11-21 13:58 |
2020-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210354
|
7.5 |
HIGH
Network
|
openresty debian
|
openresty debian_linux
|
An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demonstrated by the ngx.location.capture API.
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-11724
|
2024-11-21 13:58 |
2020-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210355
|
9.8 |
CRITICAL
Network
|
dungeon_crawl_stone_soup_project
|
dungeon_crawl_stone_soup
|
Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-11722
|
2024-11-21 13:58 |
2020-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210356
|
5.4 |
MEDIUM
Network
|
etentech
|
psg-6528vm_firmware
|
eten PSG-6528VM 1.1 devices allow XSS via System Contact or System Location.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11714
|
2024-11-21 13:58 |
2020-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210357
|
7.5 |
HIGH
Network
|
wolfssl
|
wolfssl
|
wolfSSL 4.3.0 has mulmod code in wc_ecc_mulmod_ex in ecc.c that does not properly resist timing side-channel attacks.
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-11713
|
2024-11-21 13:58 |
2020-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210358
|
6.1 |
MEDIUM
Network
|
open_upload_project
|
open_upload
|
Open Upload through 0.4.3 allows XSS via index.php?action=u and the filename field.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11712
|
2024-11-21 13:58 |
2020-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210359
|
7.5 |
HIGH
Network
|
cpp-httplib_project
|
cpp-httplib
|
cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, which creates possibilities for CRLF injection and HTTP response splitting in some …
|
CWE-74
Injection
|
CVE-2020-11709
|
2024-11-21 13:58 |
2020-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210360
|
9.8 |
CRITICAL
Network
|
provideserver
|
provide_ftp_server
|
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. Privilege escalation can occur via the /ajax/SetUserInfo messages parameter because of the EXECUTE() feature, which is for execu…
|
CWE-269
Improper Privilege Management
|
CVE-2020-11708
|
2024-11-21 13:58 |
2020-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|