|
210241
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview
|
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000038eb7.
|
NVD-CWE-noinfo
|
CVE-2020-13906
|
2024-11-21 14:02 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210242
|
8.8 |
HIGH
Network
|
irfanview
|
irfanview
|
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000038ed4.
|
NVD-CWE-noinfo
|
CVE-2020-13905
|
2024-11-21 14:02 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210243
|
5.4 |
MEDIUM
Network
|
enhancesoft
|
osticket
|
scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker must be an Agent.
|
CWE-79
Cross-site Scripting
|
CVE-2020-14012
|
2024-11-21 14:02 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210244
|
6.1 |
MEDIUM
Network
|
laborator
|
xenon
|
The Laborator Xenon theme 1.3 for WordPress allows Reflected XSS via the data/typeahead-generate.php q (aka name) parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-14010
|
2024-11-21 14:02 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210245
|
8.8 |
HIGH
Network
|
j2store
|
j2store
|
The J2Store plugin before 3.3.13 for Joomla! allows a SQL injection attack by a trusted store manager.
|
CWE-89
SQL Injection
|
CVE-2020-13996
|
2024-11-21 14:02 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210246
|
5.4 |
MEDIUM
Network
|
your_online_shop_project
|
your_online_shop
|
Your Online Shop 1.8.0 allows authenticated users to trigger XSS via a Change Name or Change Surname operation.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13911
|
2024-11-21 14:02 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210247
|
8.8 |
HIGH
Adjacent
|
royalapps
|
royal_ts
|
Royal TS before 5 has a 0.0.0.0 listener, which makes it easier for attackers to bypass tunnel authentication via a brute-force approach.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-13872
|
2024-11-21 14:02 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210248
|
5.4 |
MEDIUM
Network
|
themeboy
|
sportspress
|
The SportsPress plugin before 2.7.2 for WordPress allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13892
|
2024-11-21 14:02 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210249
|
4.8 |
MEDIUM
Network
|
opencart
|
opencart
|
OpenCart 3.0.3.3 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section because of a lack of entity encoding. NOTE: this issue exists becau…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13980
|
2024-11-21 14:02 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210250
|
7.2 |
HIGH
Network
|
monstra
|
monstra_cms
|
Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute arbitrary OS commands via the Theme Module by visiting the …
|
CWE-78
OS Command
|
CVE-2020-13978
|
2024-11-21 14:02 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|