|
211221
|
8.8 |
HIGH
Network
|
piwigo
|
piwigo
|
SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager.
|
CWE-89
SQL Injection
|
CVE-2020-19217
|
2024-11-21 14:09 |
2022-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211222
|
8.8 |
HIGH
Network
|
piwigo
|
piwigo
|
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm.
|
CWE-89
SQL Injection
|
CVE-2020-19216
|
2024-11-21 14:09 |
2022-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211223
|
8.8 |
HIGH
Network
|
piwigo
|
piwigo
|
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm.
|
CWE-89
SQL Injection
|
CVE-2020-19215
|
2024-11-21 14:09 |
2022-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211224
|
9.8 |
CRITICAL
Network
|
piwigo
|
piwigo
|
SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.
|
CWE-89
SQL Injection
|
CVE-2020-19213
|
2024-11-21 14:09 |
2022-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211225
|
4.9 |
MEDIUM
Network
|
piwigo
|
piwigo
|
SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete.
|
CWE-89
SQL Injection
|
CVE-2020-19212
|
2024-11-21 14:09 |
2022-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211226
|
9.8 |
CRITICAL
Network
|
jeesite
|
jeesite
|
Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deserialization vulnerability, an attacker could exploit the vulnerability to execute …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-19229
|
2024-11-21 14:09 |
2022-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211227
|
7.5 |
HIGH
Network
|
nlnetlabs
|
ldns
|
When a zone file in ldns 1.7.1 is parsed, the function ldns_nsec3_salt_data is too trusted for the length value obtained from the zone file. When the memcpy is copied, the 0xfe - ldns_rdf_size(salt_r…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-19861
|
2024-11-21 14:09 |
2022-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211228
|
6.5 |
MEDIUM
Network
|
nlnetlabs
|
ldns
|
When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zon…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-19860
|
2024-11-21 14:09 |
2022-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211229
|
7.5 |
HIGH
Network
|
plutinosoft
|
platinum
|
Platinum Upnp SDK through 1.2.0 has a directory traversal vulnerability. The attack could remote attack victim by sending http://ip:port/../privacy.avi URL to compromise a victim's privacy.
|
CWE-22
Path Traversal
|
CVE-2020-19858
|
2024-11-21 14:09 |
2022-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211230
|
5.4 |
MEDIUM
Network
|
wuzhicms
|
wuzhi_cms
|
A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows attackers to steal the admin's cookie.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19770
|
2024-11-21 14:09 |
2021-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|