|
208971
|
5.4 |
MEDIUM
Network
|
halo
|
halo
|
Cross Sie Scripting (XSS) vulnerability in Halo 0.4.3 via CommentAuthorUrl.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18982
|
2024-11-21 14:08 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208972
|
9.8 |
CRITICAL
Network
|
halo
|
halo
|
Remote Code Executon vulnerability in Halo 0.4.3 via the remoteAddr and themeName parameters.
|
NVD-CWE-noinfo
|
CVE-2020-18980
|
2024-11-21 14:08 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208973
|
6.1 |
MEDIUM
Network
|
halo
|
halo
|
Cross Siste Scripting (XSS) vulnerablity in Halo 0.4.3 via the X-forwarded-for Header parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18979
|
2024-11-21 14:08 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208974
|
5.3 |
MEDIUM
Network
|
thinksaas
|
thinksaas
|
Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any user's photo via the "photoid%5B%5D" and "photodesc%5B%5D" parameters in the component "index.php?app…
|
NVD-CWE-Other
|
CVE-2020-18741
|
2024-11-21 14:08 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208975
|
6.1 |
MEDIUM
Network
|
zrlog
|
zrlog
|
Cross Site Scripting vulnerability in ZrLog 2.1.0 via the (1) userName and (2) email parameters in post/addComment.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18066
|
2024-11-21 14:08 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208976
|
8.8 |
HIGH
Network
|
evernote
|
evernote
|
An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the user clicks on a specially crafted URL. AK…
|
CWE-77
Command Injection
|
CVE-2020-17759
|
2024-11-21 14:08 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208977
|
6.5 |
MEDIUM
Network
|
rc_project rcpro_project
|
rc rcpro
|
An issue was discovered in function addMeByRC in the smart contract implementation for RC, an Ethereum token, allows attackers to transfer an arbitrary amount of tokens to an arbitrary address.
|
NVD-CWE-noinfo
|
CVE-2020-17753
|
2024-11-21 14:08 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208978
|
9.8 |
CRITICAL
Network
|
mon_project
|
mon
|
Integer overflow vulnerability in payable function of a smart contract implementation for an Ethereum token, as demonstrated by the smart contract implemented at address 0xB49E984A83d7A638E7F2889fc83…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-17752
|
2024-11-21 14:08 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208979
|
5.4 |
MEDIUM
Network
|
roundcube
|
webmail
|
Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18671
|
2024-11-21 14:08 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208980
|
5.4 |
MEDIUM
Network
|
roundcube
|
webmail
|
Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18670
|
2024-11-21 14:08 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|