|
199891
|
6.1 |
MEDIUM
Network
|
cxuu
|
cxuucms
|
CXUUCMS V3 allows XSS via the first and third input fields to /public/admin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29250
|
2024-11-21 14:23 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199892
|
6.1 |
MEDIUM
Network
|
cxuu
|
cxuucms
|
CXUUCMS V3 allows class="layui-input" XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29249
|
2024-11-21 14:23 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199893
|
7.2 |
HIGH
Network
|
zyxel
|
zld vpn_orchestrator nsg_firmware usg_flex_firmware
|
Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-premise before ZLD V4.39 week38, VPN Orchestrator be…
|
CWE-77
Command Injection
|
CVE-2020-29299
|
2024-11-21 14:23 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199894
|
6.1 |
MEDIUM
Network
|
xuxueli
|
xxl-job
|
XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29204
|
2024-11-21 14:23 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199895
|
9.8 |
CRITICAL
Network
|
struct2json_project
|
struct2json
|
struct2json before 2020-11-18 is affected by a Buffer Overflow because strcpy is used for S2J_STRUCT_GET_string_ELEMENT.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-29203
|
2024-11-21 14:23 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199896
|
5.5 |
MEDIUM
Local
|
tengine_project
|
tengine
|
The serializer module in OAID Tengine lite-v1.0 has a Buffer Overflow and crash. NOTE: another person has stated "I don't think there is an proof of overflow so far.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-28759
|
2024-11-21 14:23 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199897
|
6.1 |
MEDIUM
Network
|
litespeedtech
|
litespeed_cache
|
A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29172
|
2024-11-21 14:23 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199898
|
5.5 |
MEDIUM
Local
|
gnome canonical fedoraproject
|
gdk-pixbuf ubuntu_linux fedora
|
GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign t…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-29385
|
2024-11-21 14:23 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199899
|
4.8 |
MEDIUM
Network
|
wondercms
|
wondercms
|
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in Page keywords and each time any user will visit the website, the XSS triggers, …
|
CWE-79
Cross-site Scripting
|
CVE-2020-29247
|
2024-11-21 14:23 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199900
|
7.0 |
HIGH
Local
|
mariadb
|
mariadb
|
With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the n…
|
NVD-CWE-Other
|
CVE-2020-28912
|
2024-11-21 14:23 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|