|
209101
|
6.5 |
MEDIUM
Network
|
exiv2 debian
|
exiv2 debian_linux
|
A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS).
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-19716
|
2024-11-21 14:09 |
2021-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209102
|
8.8 |
HIGH
Network
|
mitre
|
caldera
|
A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.
|
CWE-78
OS Command
|
CVE-2020-19907
|
2024-11-21 14:09 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209103
|
5.4 |
MEDIUM
Network
|
ipfire
|
ipfire
|
An authenticated Stored Cross-Site Scriptiong (XSS) vulnerability exists in Lightning Wire Labs IPFire 2.21 (x86_64) - Core Update 130 in the "routing.cgi" Routing Table Entries via the "Remark" text…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19204
|
2024-11-21 14:09 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209104
|
5.4 |
MEDIUM
Network
|
netgate
|
pfsense
|
An authenticated Cross-Site Scripting (XSS) vulnerability was found in widgets/widgets/wake_on_lan_widget.php, a component of the pfSense software WebGUI, on version 2.4.4-p2 and earlier. The widget …
|
CWE-79
Cross-site Scripting
|
CVE-2020-19203
|
2024-11-21 14:09 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209105
|
5.4 |
MEDIUM
Network
|
netgate
|
pfsense
|
A Stored Cross-Site Scripting (XSS) vulnerability was found in status_filter_reload.php, a page in the pfSense software WebGUI, on Netgate pfSense version 2.4.4-p2 and earlier. The page did not encod…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19201
|
2024-11-21 14:09 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209106
|
6.1 |
MEDIUM
Network
|
typesettercms
|
typesetter
|
Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes,
|
CWE-79
Cross-site Scripting
|
CVE-2020-19511
|
2024-11-21 14:09 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209107
|
9.8 |
CRITICAL
Network
|
textpattern
|
textpattern
|
Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19510
|
2024-11-21 14:09 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209108
|
5.4 |
MEDIUM
Network
|
ipfire
|
ipfire
|
An authenticated Stored XSS (Cross-site Scripting) exists in the "captive.cgi" Captive Portal via the "Title of Login Page" text box or "TITLE" parameter in IPFire 2.21 (x86_64) - Core Update 130. It…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19202
|
2024-11-21 14:09 |
2021-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209109
|
5.4 |
MEDIUM
Network
|
issuehunt
|
boostnote
|
In Boostnote 0.12.1, exporting to PDF contains opportunities for XSS attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19924
|
2024-11-21 14:09 |
2021-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209110
|
5.3 |
MEDIUM
Network
|
dhcms_project
|
dhcms
|
An Information Disclosure vulnerability exists in dhcms 2017-09-18 when entering invalid characters after the normal interface, which causes an error that will leak the physical path.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-19275
|
2024-11-21 14:09 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|