|
208831
|
5.9 |
MEDIUM
Network
|
ietf microchip
|
public_key_cryptography_standards_\#1 microchip_libraries_for_applications
|
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbacher's oracle attack …
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-20950
|
2024-11-21 14:12 |
2021-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208832
|
6.5 |
MEDIUM
Network
|
xiph.org stepmania
|
libvorbis stepmania
|
lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE-2018-5146.
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-20412
|
2024-11-21 14:12 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208833
|
9.8 |
CRITICAL
Network
|
seacms
|
seacms
|
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.
|
CWE-89
SQL Injection
|
CVE-2020-21378
|
2024-11-21 14:12 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208834
|
9.8 |
CRITICAL
Network
|
yunyecms
|
yunyecms
|
SQL injection vulnerability in yunyecms V2.0.1 via the selcart parameter.
|
CWE-89
SQL Injection
|
CVE-2020-21377
|
2024-11-21 14:12 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208835
|
9.8 |
CRITICAL
Network
|
weiphp
|
weiphp
|
SQL injection vulnerability in the wp_where function in WeiPHP 5.0.
|
CWE-89
SQL Injection
|
CVE-2020-20300
|
2024-11-21 14:12 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208836
|
7.5 |
HIGH
Network
|
weiphp
|
weiphp
|
WeiPHP 5.0 does not properly restrict access to pages, related to using POST.
|
NVD-CWE-noinfo
|
CVE-2020-20299
|
2024-11-21 14:12 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208837
|
9.8 |
CRITICAL
Network
|
zzzcms
|
zzzphp
|
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.
|
CWE-94
Code Injection
|
CVE-2020-20298
|
2024-11-21 14:12 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208838
|
7.8 |
HIGH
Local
|
pdfresurrect_project debian fedoraproject
|
pdfresurrect debian_linux fedora
|
PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version().
|
CWE-787
Out-of-bounds Write
|
CVE-2020-20740
|
2024-11-21 14:12 |
2020-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208839
|
5.3 |
MEDIUM
Network
|
libvips debian fedoraproject
|
libvips debian_linux fedora
|
im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.
|
CWE-909
Missing Initialization of Resource
|
CVE-2020-20739
|
2024-11-21 14:12 |
2020-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208840
|
7.2 |
HIGH
Network
|
fastadmin
|
fastadmin
|
In fastadmin V1.0.0.20191212_beta, when a user with administrator rights has logged in, a malicious parameter can be passed for SQL injection in URL /admin/ajax/weigh.
|
CWE-89
SQL Injection
|
CVE-2020-21665
|
2024-11-21 14:12 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|