|
210561
|
7.8 |
HIGH
Local
|
aida64
|
aida64
|
Buffer overflow in FinalWire Ltd AIDA64 Engineer 6.00.5100 allows attackers to execute arbitrary code by creating a crafted input that will overwrite the SEH handler.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-19513
|
2024-11-21 14:09 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210562
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19364
|
2024-11-21 14:09 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210563
|
6.5 |
MEDIUM
Network
|
vtiger
|
vtiger_crm
|
Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.
|
CWE-200
Information Exposure
|
CVE-2020-19363
|
2024-11-21 14:09 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210564
|
6.1 |
MEDIUM
Network
|
vtiger
|
vtiger_crm
|
Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-part…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19362
|
2024-11-21 14:09 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210565
|
6.1 |
MEDIUM
Network
|
medintux
|
medintux
|
Reflected XSS in Medintux v2.16.000 CCAM.php by manipulating the mot1 parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web …
|
CWE-79
Cross-site Scripting
|
CVE-2020-19361
|
2024-11-21 14:09 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210566
|
7.5 |
HIGH
Network
|
fhem
|
fhem
|
Local file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a file, which can lead to sensitive information disclosure.
|
CWE-22
Path Traversal
|
CVE-2020-19360
|
2024-11-21 14:09 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210567
|
8.8 |
HIGH
Network
|
draytek
|
vigor2960_firmware
|
DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.
|
CWE-78
OS Command
|
CVE-2020-19664
|
2024-11-21 14:09 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210568
|
9.8 |
CRITICAL
Network
|
phpshe
|
phpshe
|
PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.
|
CWE-89
SQL Injection
|
CVE-2020-19165
|
2024-11-21 14:09 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210569
|
9.8 |
CRITICAL
Network
|
idreamsoft
|
icms
|
iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php.
|
CWE-78
OS Command
|
CVE-2020-19527
|
2024-11-21 14:09 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210570
|
7.8 |
HIGH
Local
|
imagemagick debian
|
imagemagick debian_linux
|
Stack-based buffer overflow and unconditional jump in ReadXPMImage in coders/xpm.c in ImageMagick 7.0.10-7.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-19667
|
2024-11-21 14:09 |
2020-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|