|
211411
|
8.8 |
HIGH
Network
|
centreon
|
centreon
|
/graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the RRDdatabase_path parameter.
|
CWE-78
OS Command
|
CVE-2020-22345
|
2024-11-21 14:13 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211412
|
7.5 |
HIGH
Network
|
joyplus-cms_project
|
joyplus-cms
|
A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information.
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2020-22124
|
2024-11-21 14:13 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211413
|
7.5 |
HIGH
Network
|
find_a_place_ljcms_project
|
find_a_place_ljcms
|
A SQL injection vulnerability in /oa.php?c=Staff&a=read of Find a Place LJCMS v 1.3 allows attackers to access sensitive database information via a crafted POST request.
|
CWE-89
SQL Injection
|
CVE-2020-22122
|
2024-11-21 14:13 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211414
|
8.8 |
HIGH
Network
|
txjia
|
imcat
|
A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitrary code.
|
CWE-94
Code Injection
|
CVE-2020-22120
|
2024-11-21 14:13 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211415
|
6.5 |
MEDIUM
Network
|
webtareas_project
|
webtareas
|
Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious user read arbitrary files.
|
CWE-22
Path Traversal
|
CVE-2020-23069
|
2024-11-21 14:13 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211416
|
6.1 |
MEDIUM
Network
|
atutor
|
atutor
|
A reflected cross site scripting (XSS) vulnerability in the /header.tmpl.php component of ATutor 2.2.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23341
|
2024-11-21 14:13 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211417
|
7.5 |
HIGH
Network
|
axiosys
|
bento4
|
A WRITE memory access in the AP4_NullTerminatedStringAtom::AP4_NullTerminatedStringAtom component of Bento4 version 06c39d9 can lead to a segmentation fault.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-23334
|
2024-11-21 14:13 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211418
|
7.5 |
HIGH
Network
|
axiosys
|
bento4
|
A heap-based buffer overflow exists in the AP4_CttsAtom::AP4_CttsAtom component located in /Core/Ap4Utils.h of Bento4 version 06c39d9. This can lead to a denial of service (DOS).
|
CWE-787
Out-of-bounds Write
|
CVE-2020-23333
|
2024-11-21 14:13 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211419
|
7.5 |
HIGH
Network
|
axiosys
|
bento4
|
A heap-based buffer overflow exists in the AP4_StdcFileByteStream::ReadPartial component located in /StdC/Ap4StdCFileByteStream.cpp of Bento4 version 06c39d9. This issue can lead to a denial of servi…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-23332
|
2024-11-21 14:13 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211420
|
7.5 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_DescriptorListWriter::Action component located in /Core/Ap4Descriptor.h. It allows an attacker to cause…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-23331
|
2024-11-21 14:13 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|