|
208151
|
7.5 |
HIGH
Network
|
stampit
|
supermixer
|
Prototype pollution in Stampit supermixer 1.0.3 allows an attacker to modify the prototype of a base object which can vary in severity depending on the implementation.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-24939
|
2024-11-21 14:16 |
2021-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208152
|
7.5 |
HIGH
Network
|
pharmacy_medical_store_and_sale_point_project
|
pharmacy_medical_store_and_sale_point
|
The catID parameter in Pharmacy Medical Store and Sale Point v1.0 has been found to be vulnerable to a Time-Based blind SQL injection via the /medical/inventories.php path which allows attackers to r…
|
CWE-89
SQL Injection
|
CVE-2020-24862
|
2024-11-21 14:16 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208153
|
8.8 |
HIGH
Network
|
libraw
|
libraw
|
Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dng_fields in identify.cpp.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-24870
|
2024-11-21 14:16 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208154
|
4.3 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage
|
CWE-352
Origin Validation Error
|
CVE-2020-24740
|
2024-11-21 14:16 |
2021-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208155
|
7.8 |
HIGH
Local
|
ui
|
unifi_video
|
In Ubiquiti UniFi Video v3.10.13, when the executable starts, its first library validation is in the current directory. This allows the impersonation and modification of the library to execute code o…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-24755
|
2024-11-21 14:16 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208156
|
5.4 |
MEDIUM
Network
|
cmswing
|
cmswing
|
There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when visitors access the article module.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24993
|
2024-11-21 14:16 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208157
|
5.4 |
MEDIUM
Network
|
cmswing
|
cmswing
|
There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when an administrator accesses the content management module.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24992
|
2024-11-21 14:16 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208158
|
9.8 |
CRITICAL
Network
|
ambarella
|
oryx_rtsp_server
|
A buffer overflow in the RTSP service of the Ambarella Oryx RTSP Server 2020-01-07 allows an unauthenticated attacker to send a crafted RTSP request, with a long digest authentication header, to exec…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-24918
|
2024-11-21 14:16 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208159
|
7.8 |
HIGH
Local
|
ffmpeg
|
ffmpeg
|
Buffer overflow vulnerability in sniff_channel_order function in aacdec_template.c in ffmpeg 3.1.2, allows attackers to execute arbitrary code (local).
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-24995
|
2024-11-21 14:16 |
2021-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208160
|
8.8 |
HIGH
Network
|
libass_project
|
libass
|
Stack overflow in the parse_tag function in libass/ass_parse.c in libass before 0.15.0 allows remote attackers to cause a denial of service or remote code execution via a crafted file.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-24994
|
2024-11-21 14:16 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|