|
209141
|
7.5 |
HIGH
Network
|
lcdf fedoraproject
|
gifsicle fedora
|
The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-19752
|
2024-11-21 14:09 |
2021-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209142
|
9.1 |
CRITICAL
Network
|
gpac
|
gpac
|
An issue was discovered in gpac 0.8.0. The gf_odf_del_ipmp_tool function in odf_code.c has a heap-based buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-19751
|
2024-11-21 14:09 |
2021-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209143
|
7.5 |
HIGH
Network
|
gpac
|
gpac
|
An issue was discovered in gpac 0.8.0. The strdup function in box_code_base.c has a heap-based buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-19750
|
2024-11-21 14:09 |
2021-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209144
|
7.2 |
HIGH
Network
|
zzcms
|
zzcms
|
A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters.
|
CWE-94
Code Injection
|
CVE-2020-19822
|
2024-11-21 14:09 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209145
|
8.8 |
HIGH
Network
|
wdoyo
|
doyocms
|
A SQL injection vulnerability in admin.php of DOYOCMS 2.3 allows attackers to execute arbitrary SQL commands via the orders[] parameter.
|
CWE-89
SQL Injection
|
CVE-2020-19821
|
2024-11-21 14:09 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209146
|
6.1 |
MEDIUM
Network
|
feehi
|
feehicms
|
Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19709
|
2024-11-21 14:09 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209147
|
9.8 |
CRITICAL
Network
|
thinkphp-zcms_project
|
thinkphp-zcms
|
thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add.
|
CWE-89
SQL Injection
|
CVE-2020-19705
|
2024-11-21 14:09 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209148
|
5.4 |
MEDIUM
Network
|
spring-boot-admin_project
|
spring-boot-admin
|
A stored cross-site scripting (XSS) vulnerability via ResourceController.java in spring-boot-admin as of 20190710 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19704
|
2024-11-21 14:09 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209149
|
6.1 |
MEDIUM
Network
|
dzzoffice
|
dzzoffice
|
A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19703
|
2024-11-21 14:09 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209150
|
6.5 |
MEDIUM
Network
|
popojicms
|
popojicms
|
Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php.
|
CWE-22
Path Traversal
|
CVE-2020-19547
|
2024-11-21 14:09 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|