|
208791
|
7.0 |
HIGH
Local
|
mpv
|
mpv
|
An issue in MPV v.0.29.1 fixed in v0.30 allows attackers to execute arbitrary code and crash program via the ao_c parameter.
|
CWE-362
Race Condition
|
CVE-2020-19824
|
2024-11-21 14:09 |
2023-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208792
|
9.6 |
CRITICAL
Network
|
kimai
|
kimai
|
Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19825
|
2024-11-21 14:09 |
2023-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208793
|
5.4 |
MEDIUM
Network
|
idera
|
yellowfin_business_intelligence
|
Cross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote attackers to run arbitrary code via MIAdminStyles.i4 Admin UI.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19587
|
2024-11-21 14:09 |
2022-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208794
|
9.0 |
CRITICAL
Network
|
yellowfinbi
|
business_intelligence
|
Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19586
|
2024-11-21 14:09 |
2022-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208795
|
6.1 |
MEDIUM
Network
|
xiuno
|
xiunobbs
|
Cross Site Scripting (XSS) in xiunobbs 4.0.4 allows remote attackers to execute arbitrary web script or HTML via the attachment upload function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19914
|
2024-11-21 14:09 |
2022-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208796
|
6.1 |
MEDIUM
Network
|
wuzhicms
|
wuzhi_cms
|
A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19897
|
2024-11-21 14:09 |
2022-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208797
|
9.8 |
CRITICAL
Network
|
1234n
|
minicms
|
File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.
|
NVD-CWE-Other
|
CVE-2020-19896
|
2024-11-21 14:09 |
2022-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208798
|
7.2 |
HIGH
Network
|
bludit
|
bludit
|
An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19228
|
2024-11-21 14:09 |
2022-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208799
|
8.8 |
HIGH
Network
|
piwigo
|
piwigo
|
SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager.
|
CWE-89
SQL Injection
|
CVE-2020-19217
|
2024-11-21 14:09 |
2022-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208800
|
8.8 |
HIGH
Network
|
piwigo
|
piwigo
|
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm.
|
CWE-89
SQL Injection
|
CVE-2020-19216
|
2024-11-21 14:09 |
2022-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|