|
208861
|
7.5 |
HIGH
Network
|
slicedinvoices
|
sliced_invoices
|
Sliced Invoices plugin for WordPress 3.8.2 and earlier allows unauthenticated information disclosure and authenticated SQL injection via core/class-sliced.php.
|
CWE-89
SQL Injection
|
CVE-2020-20625
|
2024-11-21 14:12 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208862
|
5.4 |
MEDIUM
Network
|
cookielawinfo
|
gdpr_cookie_consent
|
ajax_policy_generator in admin/modules/cli-policy-generator/classes/class-policy-generator-ajax.php in GDPR Cookie Consent (cookie-law-info) 1.8.2 and below plugin for WordPress, allows authenticated…
|
CWE-79
Cross-site Scripting
|
CVE-2020-20633
|
2024-11-21 14:12 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208863
|
6.5 |
MEDIUM
Network
|
elementor
|
website_builder
|
Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.
|
NVD-CWE-noinfo
|
CVE-2020-20634
|
2024-11-21 14:12 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208864
|
7.5 |
HIGH
Network
|
mikrotik
|
routeros
|
An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-20021
|
2024-11-21 14:11 |
2023-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208865
|
5.5 |
MEDIUM
Local
|
avast
|
antivirus
|
Buffer Overflow vulnerability in Avast AntiVirus before v.19.7 allows a local attacker to cause a denial of service via a crafted request to the aswSnx.sys driver.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-20118
|
2024-11-21 14:11 |
2023-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208866
|
8.8 |
HIGH
Network
|
bludit
|
bludit
|
Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20210
|
2024-11-21 14:11 |
2023-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208867
|
6.1 |
MEDIUM
Network
|
diaowen
|
dwsurvey
|
Cross Site Scripting vulnerability found in wkeyuan DWSurvey 1.0 allows a remote attacker to execute arbitrary code via thequltemld parameter of the qu-multi-fillblank!answers.action file.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20070
|
2024-11-21 14:11 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208868
|
8.8 |
HIGH
Network
|
ebcms
|
ebcms
|
File upload vulnerability in ebCMS v.1.1.0 allows a remote attacker to execute arbitrary code via the upload type parameter.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20067
|
2024-11-21 14:11 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208869
|
9.8 |
CRITICAL
Network
|
sudytech
|
webplus_pro
|
WebPlus Pro v1.4.7.8.4-01 is vulnerable to Incorrect Access Control.
|
CWE-22
Path Traversal
|
CVE-2020-20012
|
2024-11-21 14:11 |
2023-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208870
|
7.2 |
HIGH
Network
|
moodle
|
moodle
|
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.
|
CWE-20
Improper Input Validation
|
CVE-2020-1756
|
2024-11-21 14:11 |
2022-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|