|
208691
|
9.8 |
CRITICAL
Network
|
yaws debian canonical
|
yaws debian_linux ubuntu_linux
|
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
|
CWE-611
XXE
|
CVE-2020-24379
|
2024-11-21 14:14 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208692
|
9.8 |
CRITICAL
Network
|
projectworlds
|
car_rental_project
|
Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-24199
|
2024-11-21 14:14 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208693
|
6.1 |
MEDIUM
Network
|
stock_management_system_project
|
stock_management_system
|
A persistent cross-site scripting vulnerability in Sourcecodester Stock Management System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'Brand Name.'
|
CWE-79
Cross-site Scripting
|
CVE-2020-24198
|
2024-11-21 14:14 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208694
|
9.1 |
CRITICAL
Network
|
online_bike_rental_project
|
online_bike_rental
|
An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated administrator to conduct remote code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-24195
|
2024-11-21 14:14 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208695
|
9.8 |
CRITICAL
Network
|
stock_management_system_project
|
stock_management_system
|
A SQL injection vulnerability in the login component in Stock Management System v1.0 allows remote attacker to execute arbitrary SQL commands via the username parameter.
|
CWE-89
SQL Injection
|
CVE-2020-24197
|
2024-11-21 14:14 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208696
|
6.1 |
MEDIUM
Network
|
daily_tracker_system_project
|
daily_tracker_system
|
A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' paramete…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24194
|
2024-11-21 14:14 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208697
|
9.8 |
CRITICAL
Network
|
silk-v3-decoder_project
|
silk-v3-decoder
|
The decode program in silk-v3-decoder Version:20160922 Build By kn007 does not strictly check data, resulting in a buffer overflow.
|
CWE-119 CWE-20
Incorrect Access of Indexable Resource ('Range Error') Improper Input Validation
|
CVE-2020-24074
|
2024-11-21 14:14 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208698
|
7.8 |
HIGH
Local
|
realtimelogic
|
barracudadrive
|
Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by replacing the %SYSTEMDRIVE%\bd\bd.exe file. When th…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-23834
|
2024-11-21 14:14 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208699
|
9.8 |
CRITICAL
Network
|
daily_tracker_system_project
|
daily_tracker_system
|
A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.
|
CWE-89
SQL Injection
|
CVE-2020-24193
|
2024-11-21 14:14 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208700
|
7.8 |
HIGH
Local
|
tencent
|
tencent
|
The Shenzhen Tencent app 5.8.2.5300 for PC platforms (from Tencent App Center) has a DLL hijacking vulnerability. Attackers can use this vulnerability to execute malicious code.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-24162
|
2024-11-21 14:14 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|