|
198651
|
4.9 |
MEDIUM
Network
|
bloofox
|
bloofoxcms
|
bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../media/images/ via the admin/index.php?mode=tools&page=upload URI, aka directory t…
|
CWE-22
Path Traversal
|
CVE-2020-35709
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198652
|
7.2 |
HIGH
Network
|
phplist
|
phplist
|
phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Administrators" page.
|
CWE-89
SQL Injection
|
CVE-2020-35708
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198653
|
5.4 |
MEDIUM
Network
|
daybydaycrm
|
daybyday
|
Daybyday 2.1.0 allows stored XSS via the Company Name parameter to the New Client screen.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35707
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198654
|
5.4 |
MEDIUM
Network
|
daybydaycrm
|
daybyday
|
Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Project screen.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35706
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198655
|
5.4 |
MEDIUM
Network
|
daybydaycrm
|
daybyday
|
Daybyday 2.1.0 allows stored XSS via the Name parameter to the New User screen.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35705
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198656
|
5.4 |
MEDIUM
Network
|
daybydaycrm
|
daybyday
|
Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Lead screen.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35704
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198657
|
7.8 |
HIGH
Local
|
freedesktop
|
poppler
|
DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from Poppler git clones …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35702
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198658
|
8.8 |
HIGH
Adjacent
|
google
|
android
|
On some Samsung phones and tablets running Android through 7.1.1, it is possible for an attacker-controlled Bluetooth Low Energy (BLE) device to pair silently with a vulnerable target device, without…
|
NVD-CWE-noinfo
|
CVE-2020-35693
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198659
|
7.5 |
HIGH
Network
|
opensmtpd fedoraproject
|
opensmtpd fedora
|
smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted pattern of cl…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-35680
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198660
|
7.5 |
HIGH
Network
|
opensmtpd fedoraproject
|
opensmtpd fedora
|
smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messages to an instance that performs many regex lookups.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-35679
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|