|
198091
|
7.8 |
HIGH
Local
|
pearson
|
vue_testing_system
|
The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMDRIVE%\Pearson VUE" directory, which allows local users to obtain administrative…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-36154
|
2024-11-21 14:28 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198092
|
9.8 |
CRITICAL
Network
|
cse_bookstore_project
|
cse_bookstore
|
CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in bookPerPub.php and in cart.php. A successful exploitation of th…
|
CWE-89
SQL Injection
|
CVE-2020-36112
|
2024-11-21 14:28 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198093
|
7.5 |
HIGH
Network
|
ffmpeg debian
|
ffmpeg debian_linux
|
decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35965
|
2024-11-21 14:28 |
2021-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198094
|
6.5 |
MEDIUM
Network
|
ffmpeg
|
ffmpeg
|
track_header in libavformat/vividas.c in FFmpeg 4.3.1 has an out-of-bounds write because of incorrect extradata packing.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35964
|
2024-11-21 14:28 |
2021-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198095
|
7.8 |
HIGH
Local
|
treasuredata
|
fluent_bit
|
flb_gzip_compress in flb_gzip.c in Fluent Bit before 1.6.4 has an out-of-bounds write because it does not use the correct calculation of the maximum gzip data-size expansion.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35963
|
2024-11-21 14:28 |
2021-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198096
|
7.5 |
HIGH
Network
|
loopring
|
loopring
|
The sellTokenForLRC function in the vault protocol in the smart contract implementation for Loopring (LRC), an Ethereum token, lacks access control for fee swapping and thus allows price manipulation.
|
NVD-CWE-noinfo
|
CVE-2020-35962
|
2024-11-21 14:28 |
2021-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198097
|
6.5 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
login.php in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 generates error messages that distinguish between incorrect username and incorrect password (i.e., not a single "Incorrect user…
|
NVD-CWE-noinfo
|
CVE-2020-35952
|
2024-11-21 14:28 |
2021-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198098
|
9.9 |
CRITICAL
Network
|
expresstech
|
quiz_and_survey_master
|
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offl…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-35951
|
2024-11-21 14:28 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198099
|
8.8 |
HIGH
Network
|
xcloner
|
xcloner
|
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).
|
CWE-352
Origin Validation Error
|
CVE-2020-35950
|
2024-11-21 14:28 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198100
|
9.8 |
CRITICAL
Network
|
expresstech
|
quiz_and_survey_master
|
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution.…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-35949
|
2024-11-21 14:28 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|