|
199931
|
6.1 |
MEDIUM
Network
|
kamalkhan
|
kk_star_ratings
|
Cross Site Scripting (XSS) vulnerability in the kk Star Ratings plugin before 4.1.5.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35438
|
2024-11-21 14:27 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199932
|
7.8 |
HIGH
Local
|
linux netapp
|
linux_kernel cloud_backup solidfire_baseboard_management_controller_firmware h300s_firmware h500s_firmware h700s_firmware h300e_firmware h500e_firmware h700e_firmware h410s…
|
An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bounds check failure allows a local attacker with a user account on the sy…
|
-
|
CVE-2020-35519
|
2024-11-21 14:27 |
2021-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199933
|
9.8 |
CRITICAL
Network
|
inxedu
|
inxedu
|
SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to admin/letter/delsystem.
|
CWE-89
SQL Injection
|
CVE-2020-35430
|
2024-11-21 14:27 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199934
|
5.4 |
MEDIUM
Network
|
unisys
|
data_exchange_management_studio
|
Unisys Data Exchange Management Studio through 5.0.34 doesn't sanitize the input to a HTML document field. This could be used for an XSS attack.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35542
|
2024-11-21 14:27 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199935
|
9.8 |
CRITICAL
Network
|
wondercms
|
wondercms
|
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary cod…
|
CWE-78
OS Command
|
CVE-2020-35314
|
2024-11-21 14:27 |
2021-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199936
|
9.8 |
CRITICAL
Network
|
wondercms
|
wondercms
|
A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL t…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-35313
|
2024-11-21 14:27 |
2021-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199937
|
5.4 |
MEDIUM
Network
|
monicahq
|
monica
|
Cross Site Scripting (XSS) in Monica before 2.19.1 via the journal page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35660
|
2024-11-21 14:27 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199938
|
6.1 |
MEDIUM
Network
|
group-office
|
group_office
|
Cross Site Scripting (XSS) in Group Office CRM 6.4.196 via the SET_LANGUAGE parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35419
|
2024-11-21 14:27 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199939
|
5.4 |
MEDIUM
Network
|
group-office
|
group_office
|
Cross Site Scripting (XSS) in the contact page of Group Office CRM 6.4.196 by uploading a crafted svg file.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35418
|
2024-11-21 14:27 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199940
|
9.8 |
CRITICAL
Network
|
conquest_dicom_server_project
|
conquest_dicom_server
|
CONQUEST DICOM SERVER before 1.5.0 has a code execution vulnerability which can be exploited by attackers to execute malicious code.
|
NVD-CWE-noinfo
|
CVE-2020-35308
|
2024-11-21 14:27 |
2021-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|