|
208461
|
5.4 |
MEDIUM
Network
|
naviwebs
|
navigatecms
|
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) via the module "Shop."
|
CWE-79
Cross-site Scripting
|
CVE-2020-23654
|
2024-11-21 14:13 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208462
|
6.5 |
MEDIUM
Network
|
sysax
|
multi_server
|
When uploading a file in Sysax Multi Server 6.90, an authenticated user can modify the filename="" parameter in the uploadfile_name1.htm form to a length of 368 or more bytes. This will create a buff…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-23574
|
2024-11-21 14:13 |
2020-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208463
|
7.8 |
HIGH
Local
|
pnotes.net_project
|
pnotes.net
|
A File Upload Vulnerability in PNotes - Andrey Gruber PNotes.NET v3.8.1.2 allows a local attacker to execute arbitrary code via the Miscellaneous " External Programs by uploading the malicious .exe f…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-22721
|
2024-11-21 14:13 |
2020-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208464
|
7.8 |
HIGH
Local
|
rapidscada
|
rapid_scada
|
Rapid Software LLC Rapid SCADA 5.8.0 is affected by a local privilege escalation vulnerability in the ScadaAgentSvc.exe executable file. An attacker can obtain admin privileges by placing a malicious…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-22722
|
2024-11-21 14:13 |
2020-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208465
|
7.8 |
HIGH
Local
|
ogg_video_tools_project
|
ogg_video_tools
|
Buffer Overflow vulnerability in ExtractorInformation function in streamExtractor.cpp in oggvideotools 0.9.1 allows remaote attackers to run arbitrary code via opening of crafted ogg file.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-21724
|
2024-11-21 14:12 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208466
|
7.8 |
HIGH
Local
|
freeimage_project
|
freeimage
|
Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-21427
|
2024-11-21 14:12 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208467
|
7.5 |
HIGH
Network
|
openvpn
|
openvpn
|
Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.
|
NVD-CWE-noinfo
|
CVE-2020-20813
|
2024-11-21 14:12 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208468
|
7.5 |
HIGH
Network
|
phpok
|
phpok
|
SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist function in framerwork/phpok_call.php file.
|
CWE-89
SQL Injection
|
CVE-2020-21486
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208469
|
6.1 |
MEDIUM
Network
|
taogogo
|
taocms
|
Cross Site Scripting vulnerability in taogogo taoCMS v.2.5 beta5.1 allows remote attacker to execute arbitrary code via the name field in admin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20725
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208470
|
4.8 |
MEDIUM
Network
|
nodcms
|
nodcms
|
Cross Site Scripting vulnerability in khodakhah NodCMS v.3.0 allows a remote attacker to execute arbitrary code and gain access to senstivie information via a crafted script to the address parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20697
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|