|
208891
|
5.4 |
MEDIUM
Network
|
bigtreecms
|
bigtree_cms
|
Cross Site Scripting (XSS) vulnerabilty exists in BigTree-CMS 4.4.3 in the tag name field found in the Tags page under the General menu via a crafted website name by doing an authenticated POST HTTP …
|
CWE-79
Cross-site Scripting
|
CVE-2020-18467
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208892
|
5.4 |
MEDIUM
Network
|
popojicms
|
popojicms
|
Cross Site Scripting (XSS) vulnerability exists in PopojiCMS 2.0.1 in admin.php?mod=menumanager--------- edit menu.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18065
|
2024-11-21 14:08 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208893
|
5.5 |
MEDIUM
Local
|
broadcom
|
tcpreplay
|
Buffer Overflow in Tcpreplay v4.3.2 allows attackers to cause a Denial of Service via the 'do_checksum' function in 'checksum.c'. It can be triggered by sending a crafted pcap file to the 'tcpreplay-…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-18976
|
2024-11-21 14:08 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208894
|
3.3 |
LOW
Local
|
nasm
|
netwide_assembler
|
Buffer Overflow in Netwide Assembler (NASM) v2.15.xx allows attackers to cause a denial of service via 'crc64i' in the component 'nasmlib/crc64'. This issue is different than CVE-2019-7147.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-18974
|
2024-11-21 14:08 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208895
|
5.5 |
MEDIUM
Local
|
podofo_project
|
podofo
|
Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-18972
|
2024-11-21 14:08 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208896
|
5.5 |
MEDIUM
Local
|
podofo_project
|
podofo
|
Stack-based Buffer Overflow in PoDoFo v0.9.6 allows attackers to cause a denial of service via the component 'src/base/PdfDictionary.cpp:65'.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-18971
|
2024-11-21 14:08 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208897
|
8.8 |
HIGH
Network
|
dedecms
|
dedecms
|
The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.
|
CWE-352
Origin Validation Error
|
CVE-2020-18917
|
2024-11-21 14:08 |
2021-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208898
|
7.5 |
HIGH
Network
|
ecisp
|
espcms-p8
|
EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via the attr_array parameter. This vulnerability allows attackers to access sensitive…
|
CWE-89
SQL Injection
|
CVE-2020-18913
|
2024-11-21 14:08 |
2021-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208899
|
6.5 |
MEDIUM
Network
|
libav
|
libav
|
In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_p_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-18778
|
2024-11-21 14:08 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208900
|
6.5 |
MEDIUM
Network
|
libav
|
libav
|
In Libav 12.3, there is a segmentation fault in vc1_decode_b_mb_intfr in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-18776
|
2024-11-21 14:08 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|