|
198011
|
7.8 |
HIGH
Local
|
gpac
|
gpac
|
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function SetupWriters() in isomedia/isom_store.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-35981
|
2024-11-21 14:28 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198012
|
7.8 |
HIGH
Local
|
gpac
|
gpac
|
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is a use-after-free in the function gf_isom_box_del() in isomedia/box_funcs.c.
|
CWE-416
Use After Free
|
CVE-2020-35980
|
2024-11-21 14:28 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198013
|
7.8 |
HIGH
Local
|
gpac
|
gpac
|
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is heap-based buffer overflow in the function gp_rtp_builder_do_avc() in ietf/rtp_pck_mpeg4.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35979
|
2024-11-21 14:28 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198014
|
9.8 |
CRITICAL
Network
|
qnap
|
qts media_streaming_add-on multimedia_console
|
An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain applica…
|
CWE-89
SQL Injection
|
CVE-2020-36195
|
2024-11-21 14:28 |
2021-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198015
|
4.8 |
MEDIUM
Network
|
solarwinds
|
orion_platform
|
SolarWinds Orion Platform before 2020.2.5 allows stored XSS attacks by an administrator on the Customize View page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35856
|
2024-11-21 14:28 |
2021-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198016
|
5.3 |
MEDIUM
Network
|
redash
|
redash
|
Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks…
|
CWE-74
Injection
|
CVE-2020-36144
|
2024-11-21 14:28 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198017
|
5.4 |
MEDIUM
Network
|
baby_care_system_project
|
baby_care_system
|
Baby Care System 1.0 is affected by a cross-site scripting (XSS) vulnerability in the Edit Page tab through the Post title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35752
|
2024-11-21 14:28 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198018
|
7.2 |
HIGH
Network
|
zenphoto
|
zenphoto
|
Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the uploader plugin, check the elFinder box, and then drag a…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-36079
|
2024-11-21 14:28 |
2021-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198019
|
6.1 |
MEDIUM
Network
|
getgist
|
chatbox
|
Chatbox is affected by cross-site scripting (XSS). An attacker has to upload any XSS payload with SVG, XML file in Chatbox. There is no restriction on file upload in Chatbox which leads to stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35852
|
2024-11-21 14:28 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198020
|
6.5 |
MEDIUM
Network
|
digium
|
asterisk
|
A buffer overflow in res_pjsip_diversion.c in Sangoma Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1 allows remote attacker to crash Asterisk by deliberately misusing SIP 181 responses.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-35776
|
2024-11-21 14:28 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|