|
209081
|
9.8 |
CRITICAL
Network
|
espruino
|
espruino
|
An issue found in Espruino Espruino 6ea4c0a allows an attacker to execute arbitrrary code via oldFunc parameter of the jswrap_object.c:jswrap_function_replacewith endpoint.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-19693
|
2024-11-21 14:09 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209082
|
9.8 |
CRITICAL
Network
|
nginx
|
njs
|
Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-19692
|
2024-11-21 14:09 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209083
|
9.8 |
CRITICAL
Network
|
wide_project
|
wide
|
Directory Traversal vulnerability found in B3log Wide allows a an attacker to escalate privileges via symbolic links.
|
CWE-22
Path Traversal
|
CVE-2020-19279
|
2024-11-21 14:09 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209084
|
8.8 |
HIGH
Network
|
mm-wiki_project
|
mm-wiki
|
Cross Site Request Forgery vulnerability found in Phachon mm-wiki v.0.1.2 allows a remote attacker to execute arbitrary code via the system/user/save parameter.
|
CWE-352
Origin Validation Error
|
CVE-2020-19278
|
2024-11-21 14:09 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209085
|
5.4 |
MEDIUM
Network
|
mm-wiki_project
|
mm-wiki
|
Cross Site Scripting vulnerability found in Phachon mm-wiki v.0.1.2 allows a remote attacker to execute arbitrary code via javascript code in the markdown editor.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19277
|
2024-11-21 14:09 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209086
|
8.8 |
HIGH
Network
|
cszcms
|
csz_cms
|
File upload vulnerability in CSKaza CSZ CMS v.1.2.2 fixed in v1.2.4 allows attacker to execute aritrary commands and code via crafted PHP file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19786
|
2024-11-21 14:09 |
2023-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209087
|
7.0 |
HIGH
Local
|
mpv
|
mpv
|
An issue in MPV v.0.29.1 fixed in v0.30 allows attackers to execute arbitrary code and crash program via the ao_c parameter.
|
CWE-362
Race Condition
|
CVE-2020-19824
|
2024-11-21 14:09 |
2023-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209088
|
9.6 |
CRITICAL
Network
|
kimai
|
kimai
|
Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19825
|
2024-11-21 14:09 |
2023-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209089
|
5.4 |
MEDIUM
Network
|
idera
|
yellowfin_business_intelligence
|
Cross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote attackers to run arbitrary code via MIAdminStyles.i4 Admin UI.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19587
|
2024-11-21 14:09 |
2022-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209090
|
9.0 |
CRITICAL
Network
|
yellowfinbi
|
business_intelligence
|
Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19586
|
2024-11-21 14:09 |
2022-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|