|
209101
|
7.5 |
HIGH
Network
|
nlnetlabs
|
ldns
|
When a zone file in ldns 1.7.1 is parsed, the function ldns_nsec3_salt_data is too trusted for the length value obtained from the zone file. When the memcpy is copied, the 0xfe - ldns_rdf_size(salt_r…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-19861
|
2024-11-21 14:09 |
2022-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209102
|
6.5 |
MEDIUM
Network
|
nlnetlabs
|
ldns
|
When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zon…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-19860
|
2024-11-21 14:09 |
2022-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209103
|
7.5 |
HIGH
Network
|
plutinosoft
|
platinum
|
Platinum Upnp SDK through 1.2.0 has a directory traversal vulnerability. The attack could remote attack victim by sending http://ip:port/../privacy.avi URL to compromise a victim's privacy.
|
CWE-22
Path Traversal
|
CVE-2020-19858
|
2024-11-21 14:09 |
2022-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209104
|
5.4 |
MEDIUM
Network
|
wuzhicms
|
wuzhi_cms
|
A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows attackers to steal the admin's cookie.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19770
|
2024-11-21 14:09 |
2021-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209105
|
8.8 |
HIGH
Network
|
laravel
|
framework
|
OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.
|
CWE-78
OS Command
|
CVE-2020-19316
|
2024-11-21 14:09 |
2021-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209106
|
5.4 |
MEDIUM
Network
|
zzzcms
|
zzzcms
|
A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19683
|
2024-11-21 14:09 |
2021-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209107
|
8.8 |
HIGH
Network
|
zzzcms
|
zzzcms
|
A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-19682
|
2024-11-21 14:09 |
2021-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209108
|
6.1 |
MEDIUM
Network
|
racktables_project
|
racktables
|
Cross Site Scripting (XSS) in redirect module of Racktables version 0.21.2, allows an attacker to inject arbitrary web script or HTML via the op parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19611
|
2024-11-21 14:09 |
2021-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209109
|
6.5 |
MEDIUM
Network
|
phpmywind
|
phpmywind
|
A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication.
|
CWE-352
Origin Validation Error
|
CVE-2020-19964
|
2024-11-21 14:09 |
2021-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209110
|
5.4 |
MEDIUM
Network
|
chaoji_cms_project
|
chaoji_cms
|
A stored cross-site scripting (XSS) vulnerability in the getClientIp function in /lib/tinwin.class.php of Chaoji CMS 2.39, allows attackers to execute arbitrary web scripts.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19962
|
2024-11-21 14:09 |
2021-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|