|
208881
|
9.8 |
CRITICAL
Network
|
wms_project
|
wms
|
SQL Injection in WMS v1.0 allows remote attackers to execute arbitrary code via the "username" parameter in the component "chkuser.php".
|
CWE-89
SQL Injection
|
CVE-2020-18544
|
2024-11-21 14:08 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208882
|
9.1 |
CRITICAL
Network
|
halo
|
halo
|
File Deletion vulnerability in Halo 0.4.3 via delBackup.
|
CWE-862
Missing Authorization
|
CVE-2020-19038
|
2024-11-21 14:08 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208883
|
5.3 |
MEDIUM
Network
|
halo
|
halo
|
Incorrect Access Control vulnearbility in Halo 0.4.3, which allows a malicious user to bypass encrption to view encrpted articles via cookies.
|
CWE-287
Improper Authentication
|
CVE-2020-19037
|
2024-11-21 14:08 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208884
|
5.4 |
MEDIUM
Network
|
halo
|
halo
|
Cross Sie Scripting (XSS) vulnerability in Halo 0.4.3 via CommentAuthorUrl.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18982
|
2024-11-21 14:08 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208885
|
9.8 |
CRITICAL
Network
|
halo
|
halo
|
Remote Code Executon vulnerability in Halo 0.4.3 via the remoteAddr and themeName parameters.
|
NVD-CWE-noinfo
|
CVE-2020-18980
|
2024-11-21 14:08 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208886
|
6.1 |
MEDIUM
Network
|
halo
|
halo
|
Cross Siste Scripting (XSS) vulnerablity in Halo 0.4.3 via the X-forwarded-for Header parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18979
|
2024-11-21 14:08 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208887
|
5.3 |
MEDIUM
Network
|
thinksaas
|
thinksaas
|
Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any user's photo via the "photoid%5B%5D" and "photodesc%5B%5D" parameters in the component "index.php?app…
|
NVD-CWE-Other
|
CVE-2020-18741
|
2024-11-21 14:08 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208888
|
6.1 |
MEDIUM
Network
|
zrlog
|
zrlog
|
Cross Site Scripting vulnerability in ZrLog 2.1.0 via the (1) userName and (2) email parameters in post/addComment.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18066
|
2024-11-21 14:08 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208889
|
8.8 |
HIGH
Network
|
evernote
|
evernote
|
An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the user clicks on a specially crafted URL. AK…
|
CWE-77
Command Injection
|
CVE-2020-17759
|
2024-11-21 14:08 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208890
|
6.5 |
MEDIUM
Network
|
rc_project rcpro_project
|
rc rcpro
|
An issue was discovered in function addMeByRC in the smart contract implementation for RC, an Ethereum token, allows attackers to transfer an arbitrary amount of tokens to an arbitrary address.
|
NVD-CWE-noinfo
|
CVE-2020-17753
|
2024-11-21 14:08 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|