|
209151
|
8.8 |
HIGH
Network
|
eyoucms
|
eyoucms
|
Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin_add&lang=cn.
|
CWE-352
Origin Validation Error
|
CVE-2020-19669
|
2024-11-21 14:09 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209152
|
9.8 |
CRITICAL
Network
|
metinfo
|
metinfo
|
An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the column is deleted, allowing attackers to escalate privileges.
|
CWE-22
Path Traversal
|
CVE-2020-19305
|
2024-11-21 14:09 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209153
|
7.5 |
HIGH
Network
|
metinfo
|
metinfo
|
An issue in /admin/index.php?n=system&c=filept&a=doGetFileList of Metinfo v7.0.0 allows attackers to perform a directory traversal and access sensitive information.
|
CWE-22
Path Traversal
|
CVE-2020-19304
|
2024-11-21 14:09 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209154
|
7.8 |
HIGH
Local
|
houdunren
|
hdcms
|
An arbitrary file upload vulnerability in /fileupload.php of hdcms 5.7 allows attackers to execute arbitrary code via a crafted file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19303
|
2024-11-21 14:09 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209155
|
9.8 |
CRITICAL
Network
|
vaethink
|
vaethink
|
An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a webshell via changing uploaded file suffixes to ".php".
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19302
|
2024-11-21 14:09 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209156
|
9.8 |
CRITICAL
Network
|
vaethink
|
vaethink
|
A vulnerability in the vae_admin_rule database table of vaeThink v1.0.1 allows attackers to execute arbitrary code via a crafted payload in the condition parameter.
|
CWE-863
Incorrect Authorization
|
CVE-2020-19301
|
2024-11-21 14:09 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209157
|
8.8 |
HIGH
Network
|
struktur
|
libheif
|
An issue was discovered in heif::Box_iref::get_references in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impact due to an invalid memory read.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-19499
|
2024-11-21 14:09 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209158
|
8.8 |
HIGH
Network
|
struktur
|
libheif
|
Floating point exception in function Fraction in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impacts.
|
NVD-CWE-noinfo
|
CVE-2020-19498
|
2024-11-21 14:09 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209159
|
8.8 |
HIGH
Network
|
matio_project
|
matio
|
Integer overflow vulnerability in Mat_VarReadNextInfo5 in mat5.c in tbeu matio (aka MAT File I/O Library) 1.5.17, allows attackers to cause a Denial of Service or possibly other unspecified impacts.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-19497
|
2024-11-21 14:09 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209160
|
7.8 |
HIGH
Local
|
sam2p_project
|
sam2p
|
There is a floating point exception in ReadImage that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.
|
NVD-CWE-noinfo
|
CVE-2020-19492
|
2024-11-21 14:09 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|