|
197121
|
8.8 |
HIGH
Network
|
libarchive canonical fedoraproject
|
libarchive ubuntu_linux fedora
|
archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unsp…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-9308
|
2024-11-21 14:40 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197122
|
6.5 |
MEDIUM
Network
|
icehrm
|
icehrm
|
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to user creation via service.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-9271
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197123
|
8.8 |
HIGH
Network
|
icehrm
|
icehrm
|
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to password reset via service.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-9270
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197124
|
7.2 |
HIGH
Network
|
soplanning
|
soplanning
|
SOPlanning 1.45 is vulnerable to authenticated SQL Injection that leads to command execution via the users parameter, as demonstrated by export_ical.php.
|
CWE-89
SQL Injection
|
CVE-2020-9269
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197125
|
7.5 |
HIGH
Network
|
soplanning
|
soplanning
|
SoPlanning 1.45 is vulnerable to SQL Injection in the OrderBy clause, as demonstrated by the projets.php?order=nom_createur&by= substring.
|
CWE-89
SQL Injection
|
CVE-2020-9268
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197126
|
6.5 |
MEDIUM
Network
|
soplanning
|
soplanning
|
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-9267
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197127
|
6.5 |
MEDIUM
Network
|
soplanning
|
soplanning
|
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-9266
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197128
|
8.2 |
HIGH
Network
|
ciprianmp
|
phpmychat-plus
|
phpMyChat-Plus 1.98 is vulnerable to multiple SQL injections against the deluser.php Delete User functionality, as demonstrated by pmc_username.
|
CWE-89
SQL Injection
|
CVE-2020-9265
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197129
|
5.5 |
MEDIUM
Local
|
eset
|
nod32_antivirus internet_security smart_security mobile_security smart_tv_security cyber_security
|
ESET Archive Support Module before 1296 allows virus-detection bypass via a crafted Compression Information Field in a ZIP archive. This affects versions before 1294 of Smart Security Premium, Intern…
|
CWE-436
Interpretation Conflict
|
CVE-2020-9264
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197130
|
4.3 |
MEDIUM
Network
|
google
|
site_kit
|
The Site Kit by Google plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 1.8.0 This is due to the lack of capability checks on the admin_enqueue…
|
CWE-252
Unchecked Return Value
|
CVE-2020-8934
|
2024-11-21 14:39 |
2023-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|