|
208931
|
7.5 |
HIGH
Network
|
sky_file_project
|
sky_file
|
Sky File v2.1.0 contains a directory traversal vulnerability in the FTP server which allows attackers to access sensitive data and files via 'null' path commands.
|
CWE-22
Path Traversal
|
CVE-2020-23040
|
2024-11-21 14:13 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208932
|
5.4 |
MEDIUM
Network
|
newsoftwares
|
folder_lock
|
Folder Lock v3.4.5 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Create Folder function under the 'create' module. This vulnerability allows attackers to execute …
|
CWE-79
Cross-site Scripting
|
CVE-2020-23039
|
2024-11-21 14:13 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208933
|
7.5 |
HIGH
Network
|
kumilabs
|
swift_file_transfer
|
Swift File Transfer Mobile v1.1.2 and below was discovered to contain an information disclosure vulnerability in the path parameter. This vulnerability is exploited via an error caused by including n…
|
CWE-22
Path Traversal
|
CVE-2020-23038
|
2024-11-21 14:13 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208934
|
9.8 |
CRITICAL
Network
|
portable
|
playable
|
Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.
|
CWE-94
Code Injection
|
CVE-2020-23037
|
2024-11-21 14:13 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208935
|
5.9 |
MEDIUM
Network
|
medianavi
|
smacom
|
MEDIA NAVI Inc SMACom v1.2 was discovered to contain an insecure session validation vulnerability in the session handling of the `password` authentication parameter of the wifi photo transfer module.…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-23036
|
2024-11-21 14:13 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208936
|
9.8 |
CRITICAL
Network
|
mercury
|
mer1200_firmware mer1200g_firmware
|
A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 and Mercury Router MER1200G v1.0.1.
|
CWE-78
OS Command
|
CVE-2020-22724
|
2024-11-21 14:13 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208937
|
5.5 |
MEDIUM
Local
|
gpac
|
gpac
|
Memory leak in the sgpd_parse_entry function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-22679
|
2024-11-21 14:13 |
2021-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208938
|
5.5 |
MEDIUM
Local
|
gpac
|
gpac
|
An issue was discovered in gpac 0.8.0. The gf_media_nalu_remove_emulation_bytes function in av_parsers.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted inp…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-22678
|
2024-11-21 14:13 |
2021-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208939
|
5.5 |
MEDIUM
Local
|
gpac
|
gpac
|
An issue was discovered in gpac 0.8.0. The dump_data_hex function in box_dump.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-22677
|
2024-11-21 14:13 |
2021-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208940
|
5.5 |
MEDIUM
Local
|
gpac
|
gpac
|
An issue was discovered in gpac 0.8.0. The GetGhostNum function in stbl_read.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-22675
|
2024-11-21 14:13 |
2021-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|