|
211461
|
7.5 |
HIGH
Network
|
microsoft
|
chakracore
|
There is an ASSERTION (pFuncBody->GetYieldRegister() == oldYieldRegister) failed in Js::DebugContext::RundownSourcesAndReparse in ChakraCore version 1.12.0.0-beta.
|
NVD-CWE-noinfo
|
CVE-2020-23315
|
2024-11-21 14:13 |
2022-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211462
|
7.5 |
HIGH
Network
|
dhrystone_project
|
dhrystone
|
A NULL pointer dereference in the main() function dhry_1.c of dhrystone 2.1 causes a denial of service (DoS).
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-23026
|
2024-11-21 14:13 |
2022-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211463
|
7.8 |
HIGH
Local
|
superantispyware
|
superantispyware
|
SUPERAntispyware v8.0.0.1050 was discovered to contain an issue in the component saskutil64.sys. This issue allows attackers to arbitrarily write data to the device via IOCTL 0x9C402140.
|
NVD-CWE-noinfo
|
CVE-2020-22061
|
2024-11-21 14:13 |
2021-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211464
|
9.1 |
CRITICAL
Network
|
evga
|
precision_xoc
|
The WinRin0x64.sys and WinRing0.sys low-level drivers in EVGA Precision XOC version v6.2.7 were discovered to be configured with the default security descriptor which allows attackers to access sensi…
|
NVD-CWE-noinfo
|
CVE-2020-22057
|
2024-11-21 14:13 |
2021-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211465
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview
|
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ReadXPM_W+0x0000000000000531.
|
NVD-CWE-noinfo
|
CVE-2020-23545
|
2024-11-21 14:13 |
2021-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211466
|
6.1 |
MEDIUM
Network
|
74cms
|
74cms
|
74CMS v6.0.4 was discovered to contain a cross-site scripting (XSS) vulnerability via /index.php?m=&c=help&a=help_list&key.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22421
|
2024-11-21 14:13 |
2021-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211467
|
5.4 |
MEDIUM
Network
|
shimo
|
document
|
Shimo Document v2.0.1 contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the table content text fi…
|
CWE-79
Cross-site Scripting
|
CVE-2020-22719
|
2024-11-21 14:13 |
2021-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211468
|
8.8 |
HIGH
Network
|
beescms
|
beescms
|
BEESCMS v4.0 was discovered to contain an arbitrary file upload vulnerability via the component /admin/upload.php. This vulnerability allows attackers to execute arbitrary code via a crafted image fi…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-23572
|
2024-11-21 14:13 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211469
|
9.8 |
CRITICAL
Network
|
phpjabbers
|
fundraising_script
|
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function.
|
CWE-89
SQL Injection
|
CVE-2020-22226
|
2024-11-21 14:13 |
2021-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211470
|
9.8 |
CRITICAL
Network
|
phpjabbers
|
fundraising_script
|
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function.
|
CWE-89
SQL Injection
|
CVE-2020-22225
|
2024-11-21 14:13 |
2021-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|