|
209611
|
5.5 |
MEDIUM
Local
|
google
|
android
|
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (released in China and India) software. The S Secure application does not enforce the intended password requirement for a loc…
|
NVD-CWE-noinfo
|
CVE-2020-25047
|
2024-11-21 14:17 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209612
|
5.3 |
MEDIUM
Network
|
easyjs
|
easywebpack-cli
|
Directory Traversal vulnerability in easywebpack-cli before 4.5.2 allows attackers to obtain sensitive information via crafted GET request.
|
CWE-22
Path Traversal
|
CVE-2020-24855
|
2024-11-21 14:16 |
2022-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209613
|
8.8 |
HIGH
Network
|
thedaylightstudio
|
fuel_cms
|
SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbitrary code via the col parameter to function list_items.
|
CWE-89
SQL Injection
|
CVE-2020-24950
|
2024-11-21 14:16 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209614
|
8.8 |
HIGH
Network
|
xuxueli
|
xxl-job
|
Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html …
|
CWE-352
Origin Validation Error
|
CVE-2020-24922
|
2024-11-21 14:16 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209615
|
6.5 |
MEDIUM
Network
|
davesteele
|
gnome-gmail
|
An issue was discovered in attach parameter in GNOME Gmail version 2.5.4, allows remote attackers to gain sensitive information via crafted "mailto" link.
|
NVD-CWE-noinfo
|
CVE-2020-24904
|
2024-11-21 14:16 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209616
|
6.1 |
MEDIUM
Network
|
lepton-cms
|
leptoncms
|
Cross Site Scripting (XSS) vulnerability in backend/pages/modify.php in Lepton-CMS version 4.7.0, allows remote attackers to execute arbitrary code.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24872
|
2024-11-21 14:16 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209617
|
6.5 |
MEDIUM
Network
|
cms-dev
|
cms
|
Plaintext Password vulnerability in AddAdmin.py in cms-dev/cms v1.4.rc1, allows attackers to gain sensitive information via audit logs.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-24804
|
2024-11-21 14:16 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209618
|
7.5 |
HIGH
Network
|
nexusphp
|
nexusphp
|
Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.
|
CWE-863
Incorrect Authorization
|
CVE-2020-24771
|
2024-11-21 14:16 |
2022-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209619
|
9.8 |
CRITICAL
Network
|
nexusphp
|
nexusphp
|
SQL injection vulnerability in modrules.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2020-24770
|
2024-11-21 14:16 |
2022-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209620
|
9.8 |
CRITICAL
Network
|
nexusphp
|
nexusphp
|
SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the classes parameter.
|
CWE-89
SQL Injection
|
CVE-2020-24769
|
2024-11-21 14:16 |
2022-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|