|
209291
|
7.8 |
HIGH
Local
|
libpff_project
|
libpff
|
An use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff before 20180623 allows attackers to cause a denial of service (DOS) or execute arbitrary code via a craft…
|
CWE-416
Use After Free
|
CVE-2020-18897
|
2024-11-21 14:08 |
2021-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209292
|
6.1 |
MEDIUM
Network
|
typora
|
typora
|
Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration error in the mathematical formula blocks. This is a different…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18748
|
2024-11-21 14:08 |
2021-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209293
|
8.8 |
HIGH
Network
|
dotcms
|
dotcms
|
Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocity) files.
|
CWE-74
Injection
|
CVE-2020-18875
|
2024-11-21 14:08 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209294
|
7.2 |
HIGH
Network
|
aitecms
|
aitecms
|
SQL Injection in AiteCMS v1.0 allows remote attackers to execute arbitrary code via the component "aitecms/login/diy_list.php".
|
CWE-89
SQL Injection
|
CVE-2020-18746
|
2024-11-21 14:08 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209295
|
9.8 |
CRITICAL
Network
|
tp-shop
|
tp-shop
|
SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.
|
CWE-89
SQL Injection
|
CVE-2020-18164
|
2024-11-21 14:08 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209296
|
9.8 |
CRITICAL
Network
|
quokka_project
|
quokka
|
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/views.py'.
|
CWE-611
XXE
|
CVE-2020-18705
|
2024-11-21 14:08 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209297
|
9.8 |
CRITICAL
Network
|
fusionbox
|
widgy
|
Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code via the 'image' widget in the component 'Change Widgy Page'.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-18704
|
2024-11-21 14:08 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209298
|
9.8 |
CRITICAL
Network
|
quokka_project
|
quokka
|
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/utils/atom.py'.
|
CWE-611
XXE
|
CVE-2020-18703
|
2024-11-21 14:08 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209299
|
6.1 |
MEDIUM
Network
|
quokka_project
|
quokka
|
Cross Site Scripting (XSS) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the 'Username' parameter in the component 'quokka/admin/actions.py'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18702
|
2024-11-21 14:08 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209300
|
9.8 |
CRITICAL
Network
|
talelin
|
lin-cms-flask
|
Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token u…
|
CWE-863
Incorrect Authorization
|
CVE-2020-18701
|
2024-11-21 14:08 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|