|
210111
|
7.8 |
HIGH
Local
|
pnotes.net_project
|
pnotes.net
|
A File Upload Vulnerability in PNotes - Andrey Gruber PNotes.NET v3.8.1.2 allows a local attacker to execute arbitrary code via the Miscellaneous " External Programs by uploading the malicious .exe f…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-22721
|
2024-11-21 14:13 |
2020-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210112
|
7.8 |
HIGH
Local
|
rapidscada
|
rapid_scada
|
Rapid Software LLC Rapid SCADA 5.8.0 is affected by a local privilege escalation vulnerability in the ScadaAgentSvc.exe executable file. An attacker can obtain admin privileges by placing a malicious…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-22722
|
2024-11-21 14:13 |
2020-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210113
|
7.8 |
HIGH
Local
|
ogg_video_tools_project
|
ogg_video_tools
|
Buffer Overflow vulnerability in ExtractorInformation function in streamExtractor.cpp in oggvideotools 0.9.1 allows remaote attackers to run arbitrary code via opening of crafted ogg file.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-21724
|
2024-11-21 14:12 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210114
|
7.8 |
HIGH
Local
|
freeimage_project
|
freeimage
|
Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-21427
|
2024-11-21 14:12 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210115
|
7.5 |
HIGH
Network
|
openvpn
|
openvpn
|
Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.
|
NVD-CWE-noinfo
|
CVE-2020-20813
|
2024-11-21 14:12 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210116
|
7.5 |
HIGH
Network
|
phpok
|
phpok
|
SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist function in framerwork/phpok_call.php file.
|
CWE-89
SQL Injection
|
CVE-2020-21486
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210117
|
6.1 |
MEDIUM
Network
|
taogogo
|
taocms
|
Cross Site Scripting vulnerability in taogogo taoCMS v.2.5 beta5.1 allows remote attacker to execute arbitrary code via the name field in admin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20725
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210118
|
4.8 |
MEDIUM
Network
|
nodcms
|
nodcms
|
Cross Site Scripting vulnerability in khodakhah NodCMS v.3.0 allows a remote attacker to execute arbitrary code and gain access to senstivie information via a crafted script to the address parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20697
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210119
|
7.5 |
HIGH
Network
|
portfoliocms_project
|
portfoliocms
|
Westbrookadmin portfolioCMS v1.05 allows attackers to bypass password validation and access sensitive information via session fixation.
|
CWE-287
Improper Authentication
|
CVE-2020-20402
|
2024-11-21 14:12 |
2023-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210120
|
8.8 |
HIGH
Network
|
ibarn_project
|
ibarn
|
File upload vulnerability in function upload in action/Core.class.php in zhimengzhe iBarn 1.5 allows remote attackers to run arbitrary code via avatar upload to index.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20588
|
2024-11-21 14:12 |
2022-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|