|
208911
|
8.8 |
HIGH
Network
|
simple-log_project
|
simple-log
|
Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_add_member".
|
CWE-352
Origin Validation Error
|
CVE-2020-18265
|
2024-11-21 14:08 |
2021-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208912
|
8.8 |
HIGH
Network
|
simple-log_project
|
simple-log
|
Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_edit_member".
|
CWE-352
Origin Validation Error
|
CVE-2020-18264
|
2024-11-21 14:08 |
2021-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208913
|
8.8 |
HIGH
Network
|
libjpeg-turbo
|
libjpeg-turbo
|
Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-17541
|
2024-11-21 14:08 |
2021-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208914
|
7.5 |
HIGH
Network
|
gnu
|
gama
|
A NULL-pointer deference issue was discovered in GNU_gama::set() in ellipsoid.h in Gama 2.04 which can lead to a denial of service (DOS) via segment faults caused by crafted inputs.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-18395
|
2024-11-21 14:08 |
2021-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208915
|
5.5 |
MEDIUM
Local
|
cesanta
|
mjs
|
Stack overflow vulnerability in parse_array Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
|
CWE-674
Uncontrolled Recursion
|
CVE-2020-18392
|
2024-11-21 14:08 |
2021-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208916
|
4.8 |
MEDIUM
Network
|
phpmywind
|
phpmywind
|
Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the parameter "$cfg_switchshow" of component " /admin/web_config.php".
|
CWE-79
Cross-site Scripting
|
CVE-2020-18230
|
2024-11-21 14:08 |
2021-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208917
|
4.8 |
MEDIUM
Network
|
phpmywind
|
phpmywind
|
Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the parameter "$cfg_copyright" of component " /admin/web_config.php".
|
CWE-79
Cross-site Scripting
|
CVE-2020-18229
|
2024-11-21 14:08 |
2021-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208918
|
7.4 |
HIGH
Network
|
apache
|
fineract
|
Apache Fineract prior to 1.5.0 disables HTTPS hostname verification in ProcessorHelper in the configureClient method. Under typical deployments, a man in the middle attack could be successful.
|
NVD-CWE-Other
|
CVE-2020-17514
|
2024-11-21 14:08 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208919
|
6.1 |
MEDIUM
Network
|
typora
|
typora
|
Cross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during block rendering of a mathematical formula.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18221
|
2024-11-21 14:08 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208920
|
7.5 |
HIGH
Network
|
html-js
|
doracms
|
Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt or IV for its AES-CBC encryption, causes password encrypted …
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-18220
|
2024-11-21 14:08 |
2021-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|