|
208481
|
7.2 |
HIGH
Network
|
phplist
|
phplist
|
phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Administrators" page.
|
CWE-89
SQL Injection
|
CVE-2020-35708
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208482
|
5.4 |
MEDIUM
Network
|
daybydaycrm
|
daybyday
|
Daybyday 2.1.0 allows stored XSS via the Company Name parameter to the New Client screen.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35707
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208483
|
5.4 |
MEDIUM
Network
|
daybydaycrm
|
daybyday
|
Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Project screen.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35706
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208484
|
5.4 |
MEDIUM
Network
|
daybydaycrm
|
daybyday
|
Daybyday 2.1.0 allows stored XSS via the Name parameter to the New User screen.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35705
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208485
|
5.4 |
MEDIUM
Network
|
daybydaycrm
|
daybyday
|
Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Lead screen.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35704
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208486
|
7.8 |
HIGH
Local
|
freedesktop
|
poppler
|
DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from Poppler git clones …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35702
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208487
|
8.8 |
HIGH
Adjacent
|
google
|
android
|
On some Samsung phones and tablets running Android through 7.1.1, it is possible for an attacker-controlled Bluetooth Low Energy (BLE) device to pair silently with a vulnerable target device, without…
|
NVD-CWE-noinfo
|
CVE-2020-35693
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208488
|
7.5 |
HIGH
Network
|
opensmtpd fedoraproject
|
opensmtpd fedora
|
smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted pattern of cl…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-35680
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208489
|
7.5 |
HIGH
Network
|
opensmtpd fedoraproject
|
opensmtpd fedora
|
smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messages to an instance that performs many regex lookups.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-35679
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208490
|
6.1 |
MEDIUM
Network
|
pi-hole
|
pi-hole
|
The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indirectly query DNS with a malicious hostname can cause arbitrary JavaScript to exe…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35659
|
2024-11-21 14:27 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|