|
198021
|
7.5 |
HIGH
Network
|
online_book_store_project
|
online_book_store
|
The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads to the ability to retrieve all databases.
|
CWE-89
SQL Injection
|
CVE-2020-36003
|
2024-11-21 14:28 |
2021-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198022
|
7.5 |
HIGH
Network
|
seat-reservation-system_project
|
seat-reservation-system
|
Seat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id parameter where attackers can obtain sensitive database information.
|
CWE-89
SQL Injection
|
CVE-2020-36002
|
2024-11-21 14:28 |
2021-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198023
|
9.8 |
CRITICAL
Network
|
citsmart
|
citsmart
|
CITSmart before 9.1.2.23 allows LDAP Injection.
|
CWE-74
Injection
|
CVE-2020-35775
|
2024-11-21 14:28 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198024
|
6.5 |
MEDIUM
Network
|
imagely
|
nextgen_gallery
|
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parame…
|
CWE-352
Origin Validation Error
|
CVE-2020-35943
|
2024-11-21 14:28 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198025
|
8.8 |
HIGH
Network
|
imagely
|
nextgen_gallery
|
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execut…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2020-35942
|
2024-11-21 14:28 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198026
|
8.8 |
HIGH
Network
|
symonics fedoraproject
|
libmysofa fedora
|
Buffer overflow in readDataVar in hdf/dataobject.c in Symonics libmysofa 0.5 - 1.1 allows attackers to execute arbitrary code via a crafted SOFA.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-36152
|
2024-11-21 14:28 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198027
|
6.5 |
MEDIUM
Network
|
symonics fedoraproject
|
libmysofa fedora
|
Incorrect handling of input data in mysofa_resampler_reset_mem function in the libmysofa library 0.5 - 1.1 will lead to heap buffer overflow and overwriting large memory block.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-36151
|
2024-11-21 14:28 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198028
|
6.5 |
MEDIUM
Network
|
symonics fedoraproject
|
libmysofa fedora
|
Incorrect handling of input data in loudness function in the libmysofa library 0.5 - 1.1 will lead to heap buffer overflow and access to unallocated memory block.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-36150
|
2024-11-21 14:28 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198029
|
6.5 |
MEDIUM
Network
|
symonics fedoraproject
|
libmysofa fedora
|
Incorrect handling of input data in changeAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protec…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-36149
|
2024-11-21 14:28 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198030
|
6.5 |
MEDIUM
Network
|
symonics fedoraproject
|
libmysofa fedora
|
Incorrect handling of input data in verifyAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protec…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-36148
|
2024-11-21 14:28 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|