|
198271
|
7.5 |
HIGH
Network
|
gobby_project
|
gobby
|
Gobby 0.4.11 allows a NULL pointer dereference in the D-Bus handler for certain set_language calls.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-35450
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198272
|
7.5 |
HIGH
Network
|
pureftpd
|
pure-ftpd
|
Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-35359
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198273
|
6.1 |
MEDIUM
Network
|
intelliants
|
subrion_cms
|
Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35437
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198274
|
7.5 |
HIGH
Network
|
xpdfreader fedoraproject
|
xpdf fedora
|
Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35376
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198275
|
4.8 |
MEDIUM
Network
|
techkshetrainfo
|
savsoft_quiz
|
Savsoft Quiz 5 is affected by: Cross Site Scripting (XSS) via field_title (aka a title on the custom fields page).
|
CWE-79
Cross-site Scripting
|
CVE-2020-35349
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198276
|
6.5 |
MEDIUM
Network
|
cxuu
|
cxuucms
|
CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add.
|
CWE-352
Origin Validation Error
|
CVE-2020-35347
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198277
|
4.8 |
MEDIUM
Network
|
cxuu
|
cxuucms
|
CXUUCMS V3 3.1 is affected by a reflected XSS vulnerability that allows remote attackers to inject arbitrary web script or HTML via the imgurl parameter of admin.php?c=content&a=add.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35346
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198278
|
7.5 |
HIGH
Network
|
rockoa
|
xinhu
|
rainrocka xinhu 2.1.9 allows remote attackers to obtain sensitive information via an index.php?a=gettotal request in which the ajaxbool value is manipulated to be true.
|
NVD-CWE-noinfo
|
CVE-2020-35388
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198279
|
9.8 |
CRITICAL
Network
|
tp-link
|
wa901nd_firmware archer_c5_firmware archer_c7_firmware mr3420_firmware mr6400_firmware wa701nd_firmware wa801nd_firmware wdr3500_firmware wdr3600_firmware we843n_firmware
|
A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel. This affects WA901ND devices before 3.16.9(201…
|
NVD-CWE-noinfo
|
CVE-2020-35575
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198280
|
7.5 |
HIGH
Network
|
linksys
|
re6500_firmware
|
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to cause a persistent denial of service (segmentation fault) via a long /goform/langSwitch langSelectionOnly parameter.
|
NVD-CWE-noinfo
|
CVE-2020-35716
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|